论文标题

清洁NVD:全面的质量评估,改进和分析

Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses

论文作者

Anwar, Afsah, Abusnaina, Ahmed, Chen, Songqing, Li, Frank, Mohaisen, David

论文摘要

漏洞数据库是有关紧急软件安全问题的重要信息来源。从系统管理员到开发人员再到研究人员的安全专业人员都在很大程度上依赖这些数据库来跟踪漏洞并分析安全趋势。这些数据库有多可靠和准确? 在本文中,我们使用国家脆弱性数据库(NVD)探讨了这个问题,这是美国政府的脆弱性信息存储库,可以说是行业标准。通过系统的调查,我们在NVD中发现了可能影响其实际用途的不一致或不完整的数据,从而影响了诸如脆弱性出版日期,供应商的名称和受影响的产品的名称,脆弱性严重性得分以及脆弱性类型类型等信息。我们探索这些差异的程度,并确定自动校正的方法。最后,我们证明了这些数据问题可以通过使用NVD的原始版本和我们的整流版本进行分析来构成的影响。最终,我们对NVD的调查不仅产生了改进的脆弱性信息来源,而且还为安全社区提供了有关此类数据源的策划和使用的重要见解和指导。

Vulnerability databases are vital sources of information on emergent software security concerns. Security professionals, from system administrators to developers to researchers, heavily depend on these databases to track vulnerabilities and analyze security trends. How reliable and accurate are these databases though? In this paper, we explore this question with the National Vulnerability Database (NVD), the U.S. government's repository of vulnerability information that arguably serves as the industry standard. Through a systematic investigation, we uncover inconsistent or incomplete data in the NVD that can impact its practical uses, affecting information such as the vulnerability publication dates, names of vendors and products affected, vulnerability severity scores, and vulnerability type categorizations. We explore the extent of these discrepancies and identify methods for automated corrections. Finally, we demonstrate the impact that these data issues can pose by comparing analyses using the original and our rectified versions of the NVD. Ultimately, our investigation of the NVD not only produces an improved source of vulnerability information, but also provides important insights and guidance for the security community on the curation and use of such data sources.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源