Proceedings of the 14th International Conference on Evaluation of Novel Approaches to Software Engineering 2019
DOI: 10.5220/0007709902970306
|View full text |Cite
|
Sign up to set email alerts
|

CVSS-based Estimation and Prioritization for Security Risks

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
2
2
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 8 publications
(3 citation statements)
references
References 0 publications
0
3
0
Order By: Relevance
“…The same study reported that an identification of security properties in the early stages of development positively impacts the security of the systems. In the same context, Wirtz and Heisel [13] proposed a semi-automatic method to estimate security risks in the early stages of software development, using CVSS formulas to assess the threat severity. Since CVSS has already demonstrated its validity in typical IT systems, it was also adapted to calculate vulnerabilities regarding hybrid IT and IoT systems [14], [15] accurately.…”
Section: Related Work a Cvss Applicabilitymentioning
confidence: 99%
“…The same study reported that an identification of security properties in the early stages of development positively impacts the security of the systems. In the same context, Wirtz and Heisel [13] proposed a semi-automatic method to estimate security risks in the early stages of software development, using CVSS formulas to assess the threat severity. Since CVSS has already demonstrated its validity in typical IT systems, it was also adapted to calculate vulnerabilities regarding hybrid IT and IoT systems [14], [15] accurately.…”
Section: Related Work a Cvss Applicabilitymentioning
confidence: 99%
“…We have used our expert knowledge to compute these metrics, comparing them with similar vulnerabilities and following the guidelines in the CVSS manuals [36], [37]. Therefore, detected vulnerability due to the fault injection campaigns are scored, and the scores serve as a guide for risk prioritization [38] and other risk management tasks, thereby making our approach more practically useful.…”
Section: ) Cvssmentioning
confidence: 99%
“…We have used our expert knowledge to compute these metrics, comparing them with similar vulnerabilities and following the guidelines in the CVSS manuals [34], [35]. Therefore, detected vulnerability due to the fault injection campaigns are scored, and the scores serve as a guide for risk prioritization [36] and other risk management tasks, thereby making our approach more practically useful.…”
Section: B Security Risk Metricsmentioning
confidence: 99%