AutoCVSS: An Approach for Automatic Assessment of Vulnerability Severity Based on Attack Process

Deqing Zou,Ju Yang,Zhen Li,Hai Jin,Xiaojing Ma
DOI: https://doi.org/10.1007/978-3-030-19223-5_17
2019-01-01
Abstract:Vulnerability severity assessment is an important research problem. Common Vulnerability Scoring System (CVSS) has been widely used to quantitatively assess the vulnerability severity, but its assessment process relies on human experts to determine metric values, which makes the assessment process tedious and subjective. This calls for tools that can assess the vulnerability severity automatically and objectively. In this paper, we move a step forward in this direction by proposing an approach for automatic assessment of vulnerability severity based on attack process, dubbed Open image in new window (AutoCVSS). The key insight is to leverage characteristics and rules we define to model the CVSS base metrics, and assess the vulnerability severity more automatically and objectively by capturing the attributes related to the characteristics during the attack process. In order to evaluate AutoCVSS, we reproduce the attacks for 98 vulnerabilities from Linux kernel, FTP service, and Apache service with their exploits. The experimental results show that the vulnerability severity scores automatically obtained by AutoCVSS are basically in accordance with those assessed manually by security experts in the National Vulnerability Database (NVD), which verifies the effectiveness of our approach.
What problem does this paper attempt to address?