RSA: Major companies tout new vulnerability rating system
The Common Vulnerability Scoring System was unveiled yesterday
February 18, 2005 12:00 PM ETIDG News Service -
Leading IT companies including Cisco Systems Inc., Microsoft Corp. and Symantec Corp. are promoting a rating system that will standardize severity ratings of software vulnerabilities.
A plan for the new system, called the Common Vulnerability Scoring System (CVSS), was unveiled at the RSA Conference in San Francisco yesterday. If widely adopted, it would provide a common language for describing the seriousness of computer security vulnerabilities and replace vendor-specific rating systems, according to Mike Schiffman, a researcher at Cisco.
Schiffman offered a presentation on the system at RSA.
The new scoring system is part of a project by the National Infrastructure Advisory Council to create a global framework for disclosing information about security vulnerabilities. Representatives from government and the IT industry contributed to the CVSS proposal, including eBay Inc., Qualys Inc., Internet Security Systems Inc. and Mitre Corp.
NIAC, part of the U.S. Department of Homeland Security, is concerned with the security of information systems that support critical infrastructure in areas such as banking, finance, transportation, energy and manufacturing.
CVSS will use standard mathematical equations to calculate the severity of new vulnerabilities based on basic information such as whether a vulnerability can be remotely exploited or whether an attacker must log into a vulnerable system before being able to exploit a security hole, said Gerhard Eschelbeck of Qualys.
CVSS ratings will also consider timing issues, such as whether an exploit or a software patch for a specific vulnerability is available, and how long it has been available, he said.
The new rating system will be akin to the Common Vulnerabilities and Exposures (CVE) database maintained by Mitre, which provides standard identifiers and information about software holes. As with CVE, vendors will most likely use CVSS ratings as a common base of reference but continue to offer their own analysis or threat assessments, Eschelbeck said.
IT security vendors will use the CVSS in their products to evaluate and prioritize software vulnerabilities. Vendors will also be asked to provide ways for customers to enter information about their IT environment, such as the number and type of systems affected, before calculating a final CVSS rating, he said.
For example, a remotely exploitable vulnerability that affects a worker's desktop system might have a different CVSS rating than one that affects a critical payroll or human resources server, Eschelbeck said.
The system will be different from rating systems such as Symantec's ARIS attack scoring system because it will not be used as a warning system for malicious-code outbreaks, according to Schiffman's presentation.
CVSS has backing frommajor IT players and a detailed plan for implementation. However, the system doesn't yet have a home. Organizers are looking for companies or organizations, such as NIAC or Mitre, to host CVSS and provide portals for Internet users and IT vendors to access the information, Eschelbeck said.
Once it has a host and is widely implemented, CVSS will give IT administrators and vendors an easy way to assess the relative risk of software vulnerabilities and to prioritize patching on large networks, he said.
"It used to be that people never patched their systems, and that didn't work. Then the common wisdom was that you had to patch everything, and that wasn't realistic, either," Eschelbeck said.
"The truth is somewhere in the middle of the two, and prioritization is the key to that," he said.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Centralized Data Backup and Your WAN
Is your organization prepared to tackle the massive challenge of protecting your data in a cost effective and timely manner? With a growing...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
An All-in-One Approach to Web Security
Granting web access to employees poses challenges to IT administrators and introduces unique security risks. Even as companies have perfected their security techniques...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
The Hidden Dangers of Spam
Beyond the well-understood productivity drain that spam inflicts on businesses, threats posed by illicit email circulating through a network are causing many security...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
Open Source Security Myths Dispelled
(Source: Astaro) Open Source Software is computer software whose source code is available to the general public. This openly viewable nature...
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Best Practices for Backing Up VMware® with Veritas NetBackup™
VMware® is used by enterprises large and small to increase the efficiency and cost-effectiveness of their IT operations. With this in mind, Symantec...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
