Risk assessment method for IoT software supply chain vulnerabilities

Zhicheng Zhu,Kun Lan,Zhihong Rao,Yuguang Zhang
DOI: https://doi.org/10.1088/1742-6596/1732/1/012051
2021-01-01
Journal of Physics: Conference Series
Abstract:Abstract With the development of IoT technology, the number of attacks against IoT software chain vulnerabilities is greater than ever, and a reasonable vulnerability assessment system needs to be established for research. The Common Vulnerability Scoring System (CVSS) is a free, public risk assessment system used by information security vendors to assess the severity of vulnerability threats. However, CVSS is insufficient because of the strong subjectivity in the selection of measurement standards and the allocation of evaluation index weights. Based on this reason, this paper designs and proposes a more objective risk assessment method for IoT software chain vulnerabilities, and verifies the feasibility and effectiveness of the method through experiments.
English Else
What problem does this paper attempt to address?