Analysis of Cybersecurity Vulnerability Trends and Forecast Modeling
Open AccessThe nature of cyber security vulnerabilities has become more and more complex and the volume of vulnerabilities has become more overwhelming. The reporting and collection of vulnerability data has not stemmed the tidal wave of cyber security vulnerabilities This research performs analysis of the Common Vulnerability Scoring System (CVSS) vulnerability data from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) for years 1999-2017, excluding the data for the year 2011. Given the categorical nature of the data, PROC SQL queries were used to prepare the data for decision tree analysis. Developing a baseline of the CVSS data associated for reported vulnerabilities enables the creation of a forecast. The result is a method can be employed by cyber security practitioners for incorporation into their cyber security posture for decision making and assessment of against their organization’s vulnerabilities. The results the CVSS trends show the number of vulnerabilities associated to each CVSS variable and the level of variability from year to year. The CART decision tree analysis for each CVSS variable illustrate the likely influence between these variables. The Common Weakness Enumeration (CWE) forecast was generated to ascertain the outlook for this variable type. The resulting forecast shows an increase over time for the CWE variable. The detailed analysis provided by this research of CVSS trends, relationships and a potential forecast enable cyber security practitioners to understand if CVSS is indeed a valuable and informative vulnerability information to enable decision making and maintain awareness of trends in the field of cyber security vulnerability management.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.