This work evaluates the validity of the Common Vulnerability Scoring System (CVSS) Version 3 ''base score'' equation in capturing the expert opinion of its maintainers. CVSS is a widely used industry standard for rating the severity of information technology vulnerabilities; it is based on human expert opinion. This study is important because the equation design has been questioned since it has features that are both non-intuitive and unjustified by the CVSS specification. If one can show that the equation reflects CVSS expert opinion, then that study justifies the equation and the security community can treat the equation as an opaque box that functions as described. This work shows that the CVSS base score equation closely though not perfectly represents the CVSS maintainers' expert opinion. The CVSS specification itself provides a measurement of error called ''acceptable deviation'' (with a value of 0.5 points). In this work, the distance between the CVSS base scores and the closest consistent scoring systems (ones that completely conform to the recorded expert opinion) is measured. The authors calculate that the mean scoring distance is 0.13 points and the maximum scoring distance is 0.40 points. The acceptable deviation was also measured to be 0.20 points (lower than claimed by the specification). These findings validate that the CVSS base score equation represents the CVSS maintainers' domain knowledge to the extent described by these measurements.
Document Citations
Citations are generated automatically from bibliographic data
as a convenience and may not be complete or accurate.
Chicago
National Institute of Standards and Technology (NIST), Commerce Department. "Measuring the Common Vulnerability Scoring System Base Score Equation". Government. Commerce Department, November 15, 2022. https://www.govinfo.gov/app/details/GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44
APA
National Institute of Standards and Technology (NIST), Commerce Department. (2022, November 15). Measuring the Common Vulnerability Scoring System Base Score Equation. [Government]. Commerce Department. https://www.govinfo.gov/app/details/GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44
MLA
National Institute of Standards and Technology (NIST), Commerce Department. Measuring the Common Vulnerability Scoring System Base Score Equation. Commerce Department, (15 Nov 2022), https://www.govinfo.gov/app/details/GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44
Bluebook
National Institute of Standards and Technology (NIST), Commerce Department, Measuring the Common Vulnerability Scoring System Base Score Equation, GovInfo, (November 15, 2022), https://www.govinfo.gov/app/details/GOVPUB-C13-a20c2765042908b62ad4d0aec66bca44