2019
DOI: 10.1016/j.aci.2017.12.002
|View full text |Cite
|
Sign up to set email alerts
|

A look at the time delays in CVSS vulnerability scoring

Abstract: This empirical paper examines the time delays that occur between the publication of Common Vulnerabilities and Exposures (CVEs) in the National Vulnerability Database (NVD) and the Common Vulnerability Scoring System (CVSS) information attached to published CVEs. According to the empirical results based on regularized regression analysis of over eighty thousand archived vulnerabilities, (i) the CVSS content does not statistically influence the time delays, which, however, (ii) are strongly affected by a decrea… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

1
39
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
4
2
1

Relationship

2
5

Authors

Journals

citations
Cited by 59 publications
(40 citation statements)
references
References 37 publications
1
39
0
Order By: Relevance
“…2 for the intersecting subset of vulnerabilities in Safety DB that have CVEs and the corresponding vulnerabilities in NVD that have CVSS entries. Presumably due to the small delays in NVD's CVSS vulnerability scoring [20], it can be remarked that eight recent CVE-referenced vulnerabilities in Safety DB did not yet have CVSS data in NVD at the time of writing. The subset of vulnerabilities with both CVE and CVSS information indicate only relatively modest severity.…”
Section: A Overviewmentioning
confidence: 99%
“…2 for the intersecting subset of vulnerabilities in Safety DB that have CVEs and the corresponding vulnerabilities in NVD that have CVSS entries. Presumably due to the small delays in NVD's CVSS vulnerability scoring [20], it can be remarked that eight recent CVE-referenced vulnerabilities in Safety DB did not yet have CVSS data in NVD at the time of writing. The subset of vulnerabilities with both CVE and CVSS information indicate only relatively modest severity.…”
Section: A Overviewmentioning
confidence: 99%
“…This conjecture applies both to the CVSS framework [5] and to quantitative security assessments in general [41]. However, analogous reasoning does not seem to hold in the context of NVD and the second version of the CVSS standard; the content of the standard does not notably affect the delays for CVSS assignments [88]. In addition to these empirical observations, it is difficult to speculate why some particular CVSS metric would either increase or decrease the coordination and related delays [93].…”
Section: Vulnerability Metricsmentioning
confidence: 99%
“…Therefore, y i focuses on the internal coordination done by MITRE affiliates, the NVD team, and other actors involved in the coordination. One way to think about this internal coordination is to consider the delay metric as an indirect quantity for measuring how fast work items in a backlog or an inventory are transferred to complete deliveries [62,88]. Due to data limitations, however, it is currently neither possible to observe the internal within-MITRE (or within-NVD) coordination directly nor to explicitly measure the work items in the CVE backlog.…”
Section: Coordination Delaysmentioning
confidence: 99%
See 2 more Smart Citations