Evaluating the Data Inconsistency of Open-Source Vulnerability Repositories
Autor: | Yuning Jiang, Jianguo Ding, Manfred A. Jeusfeld |
---|---|
Jazyk: | angličtina |
Rok vydání: | 2021 |
Předmět: |
Vulnerability Analysis
Cybersecurity Vendor business.industry Computer science Common Vulnerabilities and Exposures National Vulnerability Database Information technology Vulnerability management Datorsystem Data Inconsistency Risk analysis (engineering) Computer Systems Data quality Data verification business Systemvetenskap informationssystem och informatik Vulnerability (computing) Information Systems |
Zdroj: | ARES |
Popis: | Modern security practices promote quantitative methods to provide prioritisation insights and support predictive analysis, which is supported by open-source cybersecurity databases such as the Common Vulnerabilities and Exposures (CVE), the National Vulnerability Database (NVD), CERT, and vendor websites. These public repositories provide a way to standardise and share up-to-date vulnerability information, with the purpose to enhance cybersecurity awareness. However, data quality issues of these vulnerability repositories may lead to incorrect prioritisation and misemployment of resources. In this paper, we aim to empirically analyse the data quality impact of vulnerability repositories for actual information technology (IT) and operating technology (OT) systems, especially on data inconsistency. Our case study shows that data inconsistency may misdirect investment of cybersecurity resources. Instead, correlated vulnerability repositories and trustworthiness data verification bring substantial benefits for vulnerability management. ©2021 Copyright held by the owner/author(s). Publication rights licensed to ACM. |
Databáze: | OpenAIRE |
Externí odkaz: |