A1 Refereed original research article in a scientific journal

A Look at the Time Delays in CVSS Vulnerability Scoring




AuthorsJukka Ruohonen

PublisherElsevier

Publication year2017

JournalApplied Computing and Informatics

eISSN2210-8327

DOIhttps://doi.org/10.1016/j.aci.2017.12.002

Web address https://www.sciencedirect.com/science/article/pii/S2210832717302995

Self-archived copy’s web addresshttps://arxiv.org/abs/1801.00938


Abstract

This empirical paper examines the time delays that occur between the publication of Common Vulnerabilities and Exposures (CVEs) in the National Vulnerability Database (NVD) and the Common Vulnerability Scoring System (CVSS) information attached to published CVEs. According to the empirical results based on regularized regression analysis of over eighty thousand archived vulnerabilities, (i) the CVSS content does not statistically influence the time delays, which, however, (ii) are strongly affected by a decreasing annual trend. In addition to these results, the paper contributes to the empirical research tradition of software vulnerabilities by a couple of insights on misuses of statistical methodology.


Downloadable publication

This is an electronic reprint of the original article.
This reprint may differ from the original in pagination and typographic detail. Please cite the original version.





Last updated on 2024-26-11 at 11:24