An Improved Scoring System for Software Vulnerability Prioritization
Ruchi Sharma () and
R. K. Singh ()
Additional contact information
Ruchi Sharma: Indira Gandhi Delhi Technical University for Women
R. K. Singh: Indira Gandhi Delhi Technical University for Women
A chapter in Quality, IT and Business Operations, 2018, pp 33-43 from Springer
Abstract:
Abstract A number of software vulnerabilities are detected during the software life cycle. Some vulnerabilities are critical and require immediate analysis and plan for their fixation, while the ones with a low damage potential can be left unattended for some time while fixing the more critical ones. Prioritization of vulnerabilities helps in determining order of vulnerability response for increased efficiency and effective utilization of resources. Existing prioritization techniques are static in their approach, and the score once generated remains associated with the vulnerability. However, the impact of the vulnerability will vary over a period of time. In this paper, we proposed a dynamic scoring system for vulnerability prioritization that takes into account two temporal attributes, namely, vulnerability index and remediation level which significantly affects the severity of a vulnerability.
Keywords: Software vulnerability; Prioritization; Temporal; Scoring (search for similar items in EconPapers)
Date: 2018
References: Add references at CitEc
Citations: View citations in EconPapers (1)
There are no downloads for this item, see the EconPapers FAQ for hints about obtaining it.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:prbchp:978-981-10-5577-5_3
Ordering information: This item can be ordered from
http://www.springer.com/9789811055775
DOI: 10.1007/978-981-10-5577-5_3
Access Statistics for this chapter
More chapters in Springer Proceedings in Business and Economics from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().