Accession Number:

AD1098014

Title:

Exploit Probabilities Conditioned on CVSS Scores

Personal Author(s):

Corporate Author:

MIT Lincoln Laboratory Lexington United States

Report Date:

2016-11-04

Abstract:

We present data-driven results that probe the relationship between the existence of cyber exploits - a stand-in for threat assessment - with CVSS scores, which are a particular metric of cyber vulnerability. Initial results indicate a roughly power-law relationship with an exponent of 75 plus or minus 14, rising to a maximum of about 9 percent for vulnerabilities with the most severe highest CVSS scores.

Descriptive Note:

Technical Report

Pages:

0015

Communities Of Interest:

Modernization Areas:

Distribution Statement:

Approved For Public Release;

Contract Number 2:

FA8721-05-C-0002, FA8702-15-D-0001

File Size:

0.53MB