共 50 条
On NVD Users' Attitudes, Experiences, Hopes, and Hurdles
被引:0
|作者:
Wunder, Julia
[1
]
Corona, Alan
[1
]
Hammer, Andreas
[1
]
Benenson, Zinaida
[1
]
机构:
[1] Friedrich Alexander Univ Erlangen Nurnberg FAU, IT Secur Infrastruct Lab, Erlangen, Germany
来源:
DIGITAL THREATS: RESEARCH AND PRACTICE
|
2024年
/
5卷
/
03期
关键词:
NVD;
National Vulnerability Database;
Vulnerabilities;
IT Security;
Survey;
User Study;
Interview;
Problems of the NVD;
D O I:
10.1145/3688806
中图分类号:
TP [自动化技术、计算机技术];
学科分类号:
0812 ;
摘要:
The National Vulnerability Database (NVD) is a major vulnerability database that is free to use for everyone. It provides information about vulnerabilities and further useful resources such as linked advisories and patches. The NVD is often considered as the central source for vulnerability information and as a help to improve the resource-intensive process of vulnerability management. Although the NVD receives much public attention, little is known about its usage in vulnerability management, users' attitudes toward it and whether they encounter any problems during usage. We explored these questions using a preliminary interview study with seven people, and a follow-up survey with 71 participants. The results show that the NVD is consulted regularly and often aids decision making. Generally, users are positive about the NVD and perceive it as a helpful, clearly structured tool. But users also faced issues: missing or incorrect entries, incomplete descriptions or incomprehensible CVSS ratings. In order to identify the problems origins, we discussed the results with two senior NVD members. Many of the problems can be attributed to higher-level problems such as the CVE List or limited resources. Nevertheless, the NVD is working on improving existing problems.
引用
收藏
页数:19
相关论文