SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Major companies team on vulnerability rating system

Major companies team on vulnerability rating system

By:  Paul Roberts  On: 20 Feb 2005 For: IDG News Service (Boston Bureau) Creator
 

Leading IT companies including Cisco Systems Inc., Microsoft Corp. and Symantec Corp. are promoting a rating system that will standardize the measurement of the severity of software vulnerabilities. A plan for the new system, called the Common Vulnerability Scoring System (CVSS), was unveiled at the RSA Conference in San Francisco on Thursday.

Leading IT companies including Cisco Systems Inc., Microsoft Corp. and Symantec Corp. are promoting a rating system that will standardize the measurement of the severity of software vulnerabilities.

A plan for the new system, called the Common Vulnerability Scoring System (CVSS), was unveiled at the RSA Conference in San Francisco on Thursday. If widely adopted, the new system will provide a common language for describing the seriousness of computer security vulnerabilities and replace different, vendor-specific rating systems, according to a presentation on the system by Mike Schiffman, a researcher at Cisco.

The new scoring system is part of a project by the National Infrastructure Advisory Council to create a global framework for disclosing information about security vulnerabilities. Representatives from across government and industry contributed to the new CVSS proposal, including eBay Inc., Qualys Inc., Internet Security Systems Inc. and Mitre Corp.

NIAC is part of the U.S. Department of Homeland Security and is concerned with the security of information systems that support critical infrastructure for areas such as banking, finance, transportation, energy and manufacturing.

CVSS will use standard mathematical equations to calculate the severity of new vulnerabilities based on basic information such as whether a vulnerability can be remotely exploited, or whether an attacker must log in to a vulnerable system before being able to take advantage of a security hole, said Gerhard Eschelbeck of Qualys.

CVSS ratings will also consider timing issues, such as whether an exploit or a software patch for a specific vulnerability is available, and how long it has been available, he said.

The new rating system will be akin to the Common Vulnerabilities and Exposures (CVE) database that is maintained by Mitre and provides standard identifiers and information about software holes. As with CVE, vendors will most likely use CVSS ratings as a common base of reference, but continue to offer their own analysis or threat assessments, Eschelbeck said.

IT security vendors will use the CVSS in their products to evaluate and prioritize software vulnerabilities. Vendors will also be asked to provide ways for customers to enter information about their IT environment, such as the number and type of systems affected, before calculating a final CVSS rating, he said.

For example, a remotely exploitable vulnerability that affects a worker's desktop system might have a different CVSS rating than one that affects a critical payroll or human resources server, Eschelbeck said.

The system will be different from rating systems such as Symantec's ARIS attack scoring system because it will not be used as a warning system for malicious code outbreaks, according to Schiffman's presentation. CVSS has backing from major IT players and a detailed plan for implementation. However, the system doesn't yet have a home. Organizers are looking for companies or organizations, such as NIAC or Mitre, to host CVSS and provide portals for Internet users and IT vendors to access the information, Eschelbeck said.


Sign up for our Newsletters

 












Print |  Views: 466   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Paul Roberts Paul Roberts is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Recent Canadian IT Jobs




Related Content

Oracle ships critical update for database, applications
Oracle ships critical update for database, applicationsWhile it continues its pursuit of BEA, the company takes a moment to focus on its own product line, fixing 51 vulnerabilities. Find out what's wrong with the import utility
Cisco releases new security products, features
Cisco releases new security products, featuresNew hardware and enhancements to a number of Cisco Systems Inc.'s software products will make computer networks more resilient to attack, the company said Tuesday.
Vendor group plans vulnerability disclosures
Vendor group plans vulnerability disclosuresA multi-vendor team led by Microsoft Corp. in late July released new guidelines for security vulnerability reporting and response. But critics of the effort faulted it for its lack of non-vendor buy-in.
Why hack a Mac?
by joaquim p. menezes - remember charlie miller? 
blog comments powered by Disqus