4.3 Article

Is Vulnerability Report Confidence Redundant? Pitfalls Using Temporal Risk Scores

期刊

IEEE SECURITY & PRIVACY
卷 19, 期 4, 页码 44-53

出版社

IEEE COMPUTER SOC
DOI: 10.1109/MSEC.2021.3070978

关键词

-

资金

  1. CAPES
  2. CNPq
  3. FAPERJ [E-26/203.215/2017, E-26/211.144/2019]

向作者/读者索取更多资源

The Common Vulnerability Scoring System score is the standard for evaluating the risk of software vulnerabilities and includes three temporal components: exploitability, remediation level, and report confidence. The discussion focuses on inferring report confidence from the first two components and highlights practical and conceptual issues in the usage of temporal risk scores.
The Common Vulnerability Scoring System score is the de facto standard to assess risk of software vulnerabilities, with three temporal components: exploitability, remediation level, and report confidence. We discuss how the latter may be inferred from the first two, pointing practical and conceptual issues in the usage of temporal risk scores.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.3
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据