Skip to main navigation Skip to search Skip to main content

Scoring Cyber Vulnerabilities based on Their Impact on Organizational Goals

  • SUNY Albany

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

12 Scopus citations

Abstract

Vulnerability Management, which is a vital part of risk and resiliency management efforts, is a continuous process of identifying, classifying, prioritizing, and removing vulnerabilities on devices that are likely to be used by attackers to compromise a network component. For effective and efficient vulnerability management, which requires extensive resources- such as time and personnel, vulnerabilities should be prioritized based on their criticality. One of the most common methods to prioritize vulnerabilities is the Common Vulnerability Scoring System (CVSS). However, in its severity score, the National Institute of Standards and Technology (NIST) only provides the base metric values that include exploitability and impact information for the known vulnerabilities and acknowledges the importance of temporal and environmental characteristics to have a more accurate vulnerability assessment. There is no established method to conduct the integration of these metrics. In this study, we created a testbed to assess the vulnerabilities by considering the functional dependencies between vulnerable assets, other assets, and business processes. The experiment results revealed that a vulnerability's severity significantly changes from its CVSS base score when the vulnerable asset's characteristics and role inside the organization are considered.

Original languageEnglish
Title of host publication2021 IEEE Systems and Information Engineering Design Symposium, SIEDS 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781665412506
DOIs
StatePublished - Apr 30 2021
Event2021 IEEE Systems and Information Engineering Design Symposium, SIEDS 2021 - Virtual, Online
Duration: Apr 30 2021 → …

Publication series

Name2021 IEEE Systems and Information Engineering Design Symposium, SIEDS 2021

Conference

Conference2021 IEEE Systems and Information Engineering Design Symposium, SIEDS 2021
CityVirtual, Online
Period04/30/21 → …

Keywords

  • CVSS
  • Cybersecurity risk
  • vulnerability scoring

Fingerprint

Dive into the research topics of 'Scoring Cyber Vulnerabilities based on Their Impact on Organizational Goals'. Together they form a unique fingerprint.

Cite this