An Improved CVSS-based Vulnerability Scoring Mechanism

Ruyi Wang,Ling Gao,Qian Sun,Deheng Sun
DOI: https://doi.org/10.1109/mines.2011.27
2011-01-01
Abstract:Through scoring vulnerabilities according to their risks, mastering statuses of vulnerabilities, security managers could adjust the configuration for computer security in time and give repair methods to different vulnerabilities flexibly. Since scoring vulnerabilities is significant for evaluating and repairing vulnerabilities, this paper presents a vulnerability scoring mechanism based on CVSS by analyzing advantages and disadvantages of CVSS and comparing with some improved CVSS-based methods. Our improved scoring mechanism makes the vulnerability evaluating more exactly and effectively, simplifying the process of vulnerability evaluating.
What problem does this paper attempt to address?