Abstract

Understanding vulnerability trends is a key component of the risk management process. The focus of this research is to analyze the trends of Common Vulnerabilities and Exposures (CVE) from the National Vulnerability Database (NVD) from 2007 to 2010. We extracted 22,521 CVEs through the four years, also collected their Common Vulnerability Scoring System (CVSS) scores from the NVD, then we analyzed the overall frequency, severity, and CVSS base metrics trends. Our finding shows that the frequency of all vulnerabilities decreased by 28% from 2007 to 2010; also, the percentage of high severity incidents decreased for that period. Over 80% of the total vulnerabilities were exploitable by network access without authentication. We further studied the trends of the select fifteen (15) vulnerability types which contain 18,427 vulnerabilities by analyzing their changes in frequency, severity, and CVSS base metrics. This research findings can help information security professionals focus their efforts in preventing and mitigating the impact of the attacks, and influence the development of security strategies developed by IS professionals as well.

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.