Print Email Facebook Twitter Estimating the Assessment Difficulty of CVSS Environmental Metrics Title Estimating the Assessment Difficulty of CVSS Environmental Metrics: An Experiment Author Allodi, Luca (Eindhoven University of Technology) Biagioni, Silvio (Università di Trento) Crispo, Bruno (Università di Trento) Labunets, K. (TU Delft Safety and Security Science) Massacci, Fabio (Università di Trento) Santos, Wagner (Università di Trento) Contributor Khanh Dang, Tran (editor) Wagner, Roland (editor) Küng, Josef (editor) Thoai, Nam (editor) Takizawa, Makoto (editor) Neuhold, Erich J. (editor) Date 2017 Abstract [Context] The CVSS framework provides several dimensions to score vulnerabilities. The environmental metrics allow security analysts to downgrade or upgrade vulnerability scores based on a company’s computing environments and security requirements. [Question] How difficult is for a human assessor to change the CVSS environmental score due to changes in security requirements (let alone technical configurations) for PCI-DSS compliance for networks and systems vulnerabilities of different type? [Results] A controlled experiment with 29 MSc students shows that given a segmented network it is significantly more difficult to apply the CVSS scoring guidelines on security requirements with respect to a flat network layout, both before and after the network has been changed to meet the PCI-DSS security requirements. The network configuration also impact the correctness of vulnerabilities assessment at system level but not at application level. [Contribution] This paper is the first attempt to empirically investigate the guidelines for the CVSS environmental metrics. We discuss theoretical and practical key aspects needed to move forward vulnerability assessments for large scale systems. To reference this document use: http://resolver.tudelft.nl/uuid:67af62d4-9be6-4d01-91ee-a662c8435bbc DOI https://doi.org/10.1007/978-3-319-70004-5_2 Publisher Springer ISBN 978-3-319-70003-8 Source Proceedings of the 4th International Conference on Future Data and Security Engineering, FDSE 2017 Event International Conference on Future Data and Security Engineering, 2017-11-29 → 2017-12-01, Ho Chi Minh City, Viet Nam Series Lecture Notes in Computer Science, 0302-9743, 10646 Part of collection Institutional Repository Document type conference paper Rights © 2017 Luca Allodi, Silvio Biagioni, Bruno Crispo, K. Labunets, Fabio Massacci, Wagner Santos Files PDF FDSE_2017_paper_34.pdf 652.74 KB Close viewer /islandora/object/uuid:67af62d4-9be6-4d01-91ee-a662c8435bbc/datastream/OBJ/view