Abstract

System vulnerabilities are ubiquitous nowadays. In 2021, millions of cyberattacks exploited system flaws resulting in billions of losses. Despite massive vulnerability databases supported by the USA and China governments, there are still several unknown issues between them. This paper proposes a methodology to compare the National Vulnerability Database (NVD), the China National Vulnerability Database (CNVD), and the China National Vulnerability Database of Information Security (CNNVD). The results reveal that the CNNVD has 1,661 vulnerabilities entries more than the NVD and at least 40 more entries regarding Chinese vendors. Moreover, there is a temporal correlation of 0.917560 between the NVD and CNNVD. To the best of the authors’ knowledge, this work is the first to normalize and compare the NVD, CNVD, and CNNVD using their data feeds.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call