A novel automatic severity vulnerability assessment framework

被引:5
|
作者
Wen, Tao [1 ]
Zhang, Yuqing [1 ,2 ]
Dong, Ying [2 ]
Yang, Gang [2 ]
机构
[1] State Key Laboratory of Integrated Services Networks, Xidian University, Xi’an
[2] National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing
来源
Journal of Communications | 2015年 / 10卷 / 05期
关键词
ASVA; Information security; Text mining; Vulnerability; Vulnerability assessment; Vulnerability database;
D O I
10.12720/jcm.10.5.320-329
中图分类号
学科分类号
摘要
Security vulnerabilities play an important role in network security. With the development of the network and the increasing number of vulnerabilities, many Quantitative Vulnerability Assessment Standards (QVAS) was proposed in order to enable professionals to prioritize the most important vulnerabilities with limited energy. However, it is difficult to apply QVAS manually due to the large number of vulnerabilities and lack of information. In order to address these problems, an Automatic Security Vulnerability Assessment Framework (ASVA) is proposed, which can automatically apply any QVAS to special Vulnerability Databases. ASVA obtain values of the metrics of a QVAS with new features of Text Mining; assign these values to a formula of QVAS and finally compute the severity values of the vulnerabilities. New features proposed in ASVA are special combinations of metrics of QVAS, so that consider the influence of metrics each other and improve the accuracy of Text Mining. Based on ASVA, CVSS as a QVAS is applied to three representative Vulnerability Databases. The results show that ASVA reduces the cost and period of the application of QVAS and promotes the standardization of security vulnerability management. © 2015 Journal of Communications.
引用
收藏
页码:320 / 329
页数:9
相关论文
共 50 条
  • [1] Towards automatic discovery and assessment of vulnerability severity in cyber-physical systems
    Jiang, Yuning
    Atif, Yacine
    ARRAY, 2022, 15
  • [2] An Automatic Software Vulnerability Classification Framework
    Davari, Maryam
    Zulkernine, Mohammad
    Jaafar, Fehmi
    PROCEEDINGS 2017 INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND ASSURANCE (ICSSA), 2017, : 44 - 49
  • [3] Automatic software vulnerability assessment by extracting vulnerability elements
    Sun, Xiaobing
    Ye, Zhenlei
    Bo, Lili
    Wu, Xiaoxue
    Wei, Ying
    Zhang, Tao
    Li, Bin
    JOURNAL OF SYSTEMS AND SOFTWARE, 2023, 204
  • [4] Conceptual Framework for Flood Vulnerability Assessment
    Borowska-Stefanska, Marta
    NATURAL HAZARDS REVIEW, 2024, 25 (03)
  • [5] Text mining based an automatic model for software vulnerability severity prediction
    Malhotra, Ruchika
    Vidushi
    INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2024, 15 (08) : 3706 - 3724
  • [6] AVIA: Automatic Vulnerability Impact Assessment on the Target System
    Tatarinova, Yuliia
    2018 IEEE SECOND INTERNATIONAL CONFERENCE ON DATA STREAM MINING & PROCESSING (DSMP), 2018, : 364 - 368
  • [7] Vulnerability and Threat Assessment Framework for Internet of Things Systems
    Beyrouti, Mohammad
    Lounis, Ahmed
    Lussier, Benjamin
    Bouadallah, Abdelmadjid
    Samhat, Abed Ellatif
    2023 6TH CONFERENCE ON CLOUD AND INTERNET OF THINGS, CIOT, 2023, : 62 - 69
  • [8] Power Grid and Natural Disasters: A Framework for Vulnerability Assessment
    Mohagheghi, Salman
    Javanbakht, Pirooz
    2015 SEVENTH ANNUAL IEEE GREEN TECHNOLOGIES CONFERENCE (GREENTECH), 2015, : 199 - 205
  • [9] A Robust Framework for Comprehensive Container Image Vulnerability Assessment
    Kim, Youngsoo
    Park, Cheolhee
    Hong, Dowon
    IEEE ACCESS, 2025, 13 : 35837 - 35847
  • [10] Vulnerability Assessment Models to Drought: Toward a Conceptual Framework
    Zarafshani, Kiumars
    Sharafi, Lida
    Azadi, Hossein
    Van Passel, Steven
    SUSTAINABILITY, 2016, 8 (06)