VRSS: A new system for rating and scoring vulnerabilities

  • Authors:
  • Qixu Liu;Yuqing Zhang

  • Affiliations:
  • National Computer Network Intrusion Protection Center, GUCAS, Beijing 100049, PR China and State Key Laboratory of Information Security, GUCAS, Beijing 100049, PR China;National Computer Network Intrusion Protection Center, GUCAS, Beijing 100049, PR China and State Key Laboratory of Information Security, GUCAS, Beijing 100049, PR China

  • Venue:
  • Computer Communications
  • Year:
  • 2011

Quantified Score

Hi-index 0.24

Visualization

Abstract

Vulnerabilities are extremely important for network security. IT management must identify and assess vulnerabilities across many disparate hardware and software platforms to prioritize these vulnerabilities and remediate those that pose the greatest risk. The focus of our research is the comparative analysis of existing vulnerability rating systems, so as to discover their respective advantages and propose a compatible rating framework to unify them. We do the statistic work on vulnerabilities of three famous vulnerability databases (IBM ISS X-Force, Vupen Security and National Vulnerability database) and analyze the distribution of vulnerabilities to expose the differences among different vulnerability rating systems. The statistical results show that the distributions of vulnerabilities are not much consistent with the normal distribution. Taking into account all kinds of existing vulnerability rating systems, we propose VRSS for qualitative rating and quantitative scoring vulnerabilities, which can combine respective advantages of all kinds of vulnerability rating systems. An experimental study of 33,654 vulnerabilities demonstrates that VRSS works well.