当网络评分系统产生分歧:一项实证比较
When Cyber Scoring Systems Diverge: An Empirical Comparison
浏览论文内容
中文总结 AI 辅助
本研究实证比较四种漏洞评分系统在2015年乌克兰电网OT网络重建中的表现,发现高度分歧,表明评分系统选择影响缓解策略,复合方法更优。
中文摘要 AI 辅助
漏洞评分系统支撑着网络补丁优先级排序和风险管理,但其比较行为几乎总是在抽象层面,通过IT漏洞数据库中的相关性研究进行评估,而非通过它们嵌入系统级风险模型时所产生的操作后果来评估。在此,我们提出对四种漏洞评分系统进行实证比较,即CVSS(通用漏洞评分系统)、EPSS(漏洞利用预测评分系统)、SSVC(利益相关者特定漏洞分类)和IronMiner(操作校准的专有评分系统)。作为比较的基底,我们使用了2015年乌克兰电网运营技术(OT)网络的重建,该网络提供了有记录的事件拓扑。结果表明,各评分系统之间存在高度分歧。这暗示着评分系统的选择可能显著影响缓解策略和漏洞优先级排序,意味着复合或混合评分方法可能提供更合适的解决方案。
英文摘要
Vulnerability scoring systems underpin cyber patch prioritization and risk management, but their comparative behavior is almost always assessed in the abstract, through correlation studies in IT vulnerability databases, rather than by the operational consequences they produce when embedded in a system-level risk model. Here we present an empirical comparison of four vulnerability scoring systems, namely CVSS (Common Vulnerability Scoring System), EPSS (Exploit Prediction Scoring System), SSVC (Stakeholder-Specific-Vulnerability Categorization), and IronMiner (operationally calibrated proprietary scoring system). As a substrate for comparison, we use a reconstruction of the 2015 Ukraine Power Grid operational-technology (OT) network that provides a documented incident topology. The results show a high degree of disagreement between the scoring systems. This suggests that the choice of the scoring system could significantly influence mitigation strategies and vulnerability prioritization, implying that a composite or hybrid scoring approach could offer a more suitable solution.
发表机构
- Aalto University School of Science(阿尔托大学理学院)
- Lockheed Martin(洛克希德·马丁)
机构由 AI 辅助整理,请以论文原文为准。