A Look at the Time Delays in CVSS Vulnerability Scoring

dc.contributor.authorJukka Ruohonen
dc.contributor.organizationfi=ohjelmistotekniikka|en=Software Engineering|
dc.contributor.organization-code2610302
dc.converis.publication-id27791900
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/27791900
dc.date.accessioned2022-10-27T12:15:15Z
dc.date.available2022-10-27T12:15:15Z
dc.description.abstract<p>This empirical paper examines the time delays that occur between the publication of Common Vulnerabilities and Exposures (CVEs) in the National Vulnerability Database (NVD) and the Common Vulnerability Scoring System (CVSS) information attached to published CVEs. According to the empirical results based on regularized regression analysis of over eighty thousand archived vulnerabilities, (i) the CVSS content does not statistically influence the time delays, which, however, (ii) are strongly affected by a decreasing annual trend. In addition to these results, the paper contributes to the empirical research tradition of software vulnerabilities by a couple of insights on misuses of statistical methodology.<br /></p>
dc.identifier.eissn2210-8327
dc.identifier.jour-issn2210-8327
dc.identifier.olddbid174239
dc.identifier.oldhandle10024/157333
dc.identifier.urihttps://www.utupub.fi/handle/11111/34062
dc.identifier.urlhttps://www.sciencedirect.com/science/article/pii/S2210832717302995
dc.identifier.urnURN:NBN:fi-fe2021042717656
dc.language.isoen
dc.okm.affiliatedauthorRuohonen, Jukka
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA1 ScientificArticle
dc.publisherElsevier
dc.publisher.countryNetherlandsen_GB
dc.publisher.countryAlankomaatfi_FI
dc.publisher.country-codeNL
dc.relation.doi10.1016/j.aci.2017.12.002
dc.relation.ispartofjournalApplied Computing and Informatics
dc.source.identifierhttps://www.utupub.fi/handle/10024/157333
dc.titleA Look at the Time Delays in CVSS Vulnerability Scoring
dc.year.issued2017

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
1801.00938.pdf
Size:
737.78 KB
Format:
Adobe Portable Document Format
Description:
Final draft