Trend analysis of the cve for software vulnerability management

YY Chang, P Zavarsky, R Ruhl… - 2011 IEEE third …, 2011 - ieeexplore.ieee.org
YY Chang, P Zavarsky, R Ruhl, D Lindskog
2011 IEEE third international conference on privacy, security …, 2011ieeexplore.ieee.org
Understanding vulnerability trends is a key component of the risk management process. The
focus of this research is to analyze the trends of Common Vulnerabilities and Exposures
(CVE) from the National Vulnerability Database (NVD) from 2007 to 2010. We extracted
22,521 CVEs through the four years, also collected their Common Vulnerability Scoring
System (CVSS) scores from the NVD, then we analyzed the overall frequency, severity, and
CVSS base metrics trends. Our finding shows that the frequency of all vulnerabilities …
Understanding vulnerability trends is a key component of the risk management process. The focus of this research is to analyze the trends of Common Vulnerabilities and Exposures (CVE) from the National Vulnerability Database (NVD) from 2007 to 2010. We extracted 22,521 CVEs through the four years, also collected their Common Vulnerability Scoring System (CVSS) scores from the NVD, then we analyzed the overall frequency, severity, and CVSS base metrics trends. Our finding shows that the frequency of all vulnerabilities decreased by 28% from 2007 to 2010; also, the percentage of high severity incidents decreased for that period. Over 80% of the total vulnerabilities were exploitable by network access without authentication. We further studied the trends of the select fifteen (15) vulnerability types which contain 18,427 vulnerabilities by analyzing their changes in frequency, severity, and CVSS base metrics. This research findings can help information security professionals focus their efforts in preventing and mitigating the impact of the attacks, and influence the development of security strategies developed by IS professionals as well.
ieeexplore.ieee.org