2021
DOI: 10.1109/msec.2020.3044475
|View full text |Cite
|
Sign up to set email alerts
|

Time to Change the CVSS?

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
24
0

Year Published

2021
2021
2023
2023

Publication Types

Select...
4
2
1

Relationship

0
7

Authors

Journals

citations
Cited by 21 publications
(24 citation statements)
references
References 6 publications
0
24
0
Order By: Relevance
“…Other than this, more advanced level evaluation starts with the help of tools such as Hping3, Nping, and Xerxes for DDoS and Authentication parameters are to be analyzed to check whether credentials of the users are in plain‐text format or hashed. In case more vulnerabilities are found, document is updated and CVSS 33 scoring system is taken into account know the severity level and impact on confidentiality, integrity and availability. All the attack results and there CVSS scores are documented.…”
Section: Methodsmentioning
confidence: 99%
“…Other than this, more advanced level evaluation starts with the help of tools such as Hping3, Nping, and Xerxes for DDoS and Authentication parameters are to be analyzed to check whether credentials of the users are in plain‐text format or hashed. In case more vulnerabilities are found, document is updated and CVSS 33 scoring system is taken into account know the severity level and impact on confidentiality, integrity and availability. All the attack results and there CVSS scores are documented.…”
Section: Methodsmentioning
confidence: 99%
“…One of the best listings of perceived faws in CVSS is [14], which also contains suggestions that could be used to improve and/or revise CVSS or to create alternate scoring systems. One concern is that in CVSS v3, the metric values are ordinals (ordered categories) but they are converted into ratio data (allowing numerical differences with a zero value) within the v3 base score equation.…”
Section: Appendix C-encoded Knowledge Constraint Graphsmentioning
confidence: 99%
“…By assigning numbers, difference relationships are established not only between ordinal values of a particular CVSS metric (e.g., privileges required), but between ordinal values of different unrelated metrics (e.g., confdentiality and attack complexity). Additionally, [14] points out that it provides no justifcation for the equation that then takes these numerical values as input. Although not mentioned in [14], many have questioned the complexity of the equation and why, for example, it has a term raised to the 15 th power.…”
Section: Appendix C-encoded Knowledge Constraint Graphsmentioning
confidence: 99%
See 1 more Smart Citation
“…Spring et al [4] from Carnegie Mellon University presented a paper explaining why the Common Vulnerability Scoring System (CVSS) [5] scores need to be more justified and transparent. They question some of the aspects of the CVSS calculation, such as the type of measurement and the translation of that measurement into numerical measure.…”
Section: Related Workmentioning
confidence: 99%