Presentation 2009-07-03
Risk Assessment Method for Networked Systems using CVSS
Toshiki HARADA, Akira KANAOKA, Eiji OKAMOTO, Masahiko KATO,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) CVSS (Common Vulnerability Scoring System) is a common vulnerability scoring method. CVSS is composed of three metrics groups: Base, Temporal, and Environmental. Currently, only the Base score is used. The Environmental score which must be used for evaluating risk of the vulnerability to each network or system environment, is hard to practical use because of its ambiguity. Recently, CVSS has been used by some researches, but Environmental score is not used in its own. We propose a method for assessing risk and setting Environmental metrics in networked systems getting rid of its ambiguity.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) CVSS / environmental score / risk assessment / network model / cloud computing
Paper # ISEC2009-34,SITE2009-26,ICSS2009-48
Date of Issue

Conference Information
Committee SITE
Conference Date 2009/6/25(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Chair
Vice Chair
Secretary
Assistant

Paper Information
Registration To Social Implications of Technology and Information Ethics (SITE)
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) Risk Assessment Method for Networked Systems using CVSS
Sub Title (in English)
Keyword(1) CVSS
Keyword(2) environmental score
Keyword(3) risk assessment
Keyword(4) network model
Keyword(5) cloud computing
1st Author's Name Toshiki HARADA
1st Author's Affiliation Graduate School of Systems and Information Engineering Department, University of Tsukuba()
2nd Author's Name Akira KANAOKA
2nd Author's Affiliation Graduate School of Systems and Information Engineering Department, University of Tsukuba
3rd Author's Name Eiji OKAMOTO
3rd Author's Affiliation Graduate School of Systems and Information Engineering Department, University of Tsukuba
4th Author's Name Masahiko KATO
4th Author's Affiliation IIJ Technology Inc.
Date 2009-07-03
Paper # ISEC2009-34,SITE2009-26,ICSS2009-48
Volume (vol) vol.109
Number (no) 114
Page pp.pp.-
#Pages 6
Date of Issue