Journal of Hebei University (Natural Science Edition) ›› 2017, Vol. 37 ›› Issue (4): 405-410.DOI: 10.3969/j.issn.1000-1565.2017.04.012脆弱性严重性动态综合量化评估方法

Previous Articles     Next Articles

A dynamic and comprehensive quantitative scoring method of vulnerability severity

GAO Ni1, HE Yiyue2, CHANG Yanshuo1, WANG Mengyang3   

  1. 1.School of Information, Xi’an University of Finance and Economics, Xi’an 710100, China; 2.School of Economics and Management, Northwest University, Xi’an 710127, China; 3.People's Bank of China Xi’an Branch, Xi’an 710075, China
  • Received:2016-08-22 Online:2017-07-25 Published:2017-07-25

Abstract: The vulnerability severity evaluation is rarely considered the dynamic indicator with changing time in the CVSS method, so the paper proposes a method of dynamic vulnerability severity assessment(DVSA).The code exploitability and the patch remediation level of dynamical indexes are introduced based on the CVSS score.Three vulnerability indexes, such as the safety influence attribute, the static vulnerability exploitability attribute and the dynamic vulnerability exploitability attribute, are selected and quantified.The vulnerability severity is evaluated with values from 0 to 10 by using the DVSA method, which can divide vulnerability severity rank into three levels: high, moderate and low.Experimental results showed that this method can more precisely distinguish the difference between vulnerabilities, and improve the diversity and accuracy of the vulnerability severity evaluation.

Key words: vulnerability, vulnerability severity evaluation, the code exploitability of vulnerability

CLC Number: