Using CVSS to quantitatively analyze risks to software caused by vulnerabilities

Quantitative methods for evaluating and managing software security are becoming reliable with the ever increasing vulnerability datasets. The Common Vulnerability Scoring System (CVSS) provides a way to quantitatively evaluate individual vulnerability. However it cannot be applied to evaluate softwa...

Full description

Bibliographic Details
Main Authors: Gao Jian-Bo, Zhang Bao-Wen, Chen Xiao-Hua
Format: Article
Language:English
Published: EDP Sciences 2015-01-01
Series:MATEC Web of Conferences
Online Access:http://dx.doi.org/10.1051/matecconf/20153116004