Improved software vulnerability patching techniques using CVSS and game theory

Louai Maghrabi, Eckhard Pfluegel, Luluwah Al-Fagih, Roman Graf, Giuseppe Settanni, Florian Skopik

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

15 Citations (Scopus)

Abstract

Software vulnerability patching is a crucial part of vulnerability management and is informed by using effective vulnerability scoring techniques. The Common Vulnerability Scoring System (CVSS) provides an open framework for assessing the severity of software vulnerabilities based on metrics capturing their individual, intrinsic characteristics. In this paper, we enhance the use of CVSS for vulnerability scoring with the help of game theory by modelling an attacker-defender scenario and arguing that, under the assumption of rational behaviour of the players, an effective vulnerability patching strategy could be achieved with an optimal strategy, solving the game. We have implemented our strategies as new functionality in the software tool CAESAIR [1]. This research builds on our previous work [2], where we have used CVSS to inform the design of the utility functions, by performing the Nash equilibrium analysis of the game. Our findings may result in more accurate defence strategies for system administrators.

Original languageEnglish
Title of host publication2017 International Conference on Cyber Security And Protection Of Digital Services, Cyber Security 2017
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781509050635
DOIs
Publication statusPublished - 18 Oct 2017
Externally publishedYes
Event2017 International Conference on Cyber Security And Protection Of Digital Services, Cyber Security 2017 - London, United Kingdom
Duration: 19 Jun 201720 Jun 2017

Publication series

Name2017 International Conference on Cyber Security And Protection Of Digital Services, Cyber Security 2017

Conference

Conference2017 International Conference on Cyber Security And Protection Of Digital Services, Cyber Security 2017
Country/TerritoryUnited Kingdom
CityLondon
Period19/06/1720/06/17

Fingerprint

Dive into the research topics of 'Improved software vulnerability patching techniques using CVSS and game theory'. Together they form a unique fingerprint.

Cite this