"CVSS is a shitty system"
Esettanulmányok arról, hogy készül a virsli CVSS (Common Vulnerability Scoring System), a cURL vezető fejlesztőjének előadásában.
@muszeresz
seen from Bulgaria
seen from Germany

seen from United States
seen from China

seen from Türkiye
seen from United States
seen from United States
seen from United Kingdom

seen from Malaysia

seen from Malaysia
seen from United States
seen from Türkiye

seen from Australia
seen from United States

seen from Germany

seen from United States

seen from United States
seen from South Africa

seen from Russia

seen from United States
"CVSS is a shitty system"
Esettanulmányok arról, hogy készül a virsli CVSS (Common Vulnerability Scoring System), a cURL vezető fejlesztőjének előadásában.
@muszeresz
What is The Common Vulnerability Scoring system (CVSS)?
The common vulnerability scoring system (CVSS) is an open and free market standard for rating the relative severity of software system vulnerabilities. CVSS refers to the Common Vulnerability Scoring System and is used in cyber investigations. Companies use this standard to assess the likelihood of installing vulnerabilities in their systems. CVSS is based on the following ideas: Security is one of the most important issues facing organizations and people today, and companies need to protect sensitive data from being stolen. Therefore, it makes sense to create a vulnerability assessment which takes into account the best protection.
Software operation policies should be developed by organizations and kept current. Frequently updating existing policies will help prevent vulnerability development. When creating a policy, it is important to consider the risk of new vulnerabilities in the system and identify those areas where the highest level of protection is not necessary. CVSS identifies a number of vulnerabilities that fall into these categories:
Remote System Integration (RSI), is when software is downloaded to a remote computer. A remote system can be a network, an internal system, or even a computer that is connected to the internet. An RSI vulnerability occurs when a remote program can access infected data. All data can be accessed, written and read, even credit card numbers.
Application Security is an important aspect of information security. Systems that contain sensitive information are the target of many programs. Executives and employees who have access to sensitive information stored on company servers need to be secure. Identity theft is one of the leading causes of system compromise; therefore, identifying and removing known exploited software is essential to reducing identity theft exposure. CVSS is a method that determines the vulnerability of an application. It does this by testing it against known vulnerabilities and threats.
Code Gateway Security, a component of network security, checks the code in applications for security flaws. The system will reject any software that is found defective. If it is allowed to run, it can potentially harm the system by executing arbitrary code on the computer. CVSS relies on algorithm-based vulnerability score to find vulnerabilities in systems. This method relies on detecting vulnerabilities in fields such as runtime, markup, and programming that are not visible to the end user.
Internet Accessibility Testing refers to a vulnerability score system used for network connections that can be accessed via the internet. Remote systems that can be accessed via the Internet could be compromised. CVSS can identify vulnerabilities in systems and attempt to fix them before they are exploited. When a system is compromised, the intruder has complete access to all data on the system. Internet accessability testing is performed to detect insecure websites and to ensure that data is not compromised by attackers who have physical access to the network.
Resource Portable Computing System (RAS) is what is common vulnerability scoring system for networks that are not only networked but also portable. This technology is designed to test hardware and software that requires peripheral devices that plug into the computer and are based on other technologies. The Secure Digital Camera (SD Card) is an example of such technology. To gain access to information stored on the device, an attacker must physically connect it to a host. RAS tests a host computer to determine whether or not it is able to implement secure transfers of the information from a removable device.
The common vulnerability scoring system, Data Collection, is widely used in many settings. The system collects information on the threats to networks such as malware, hackers, viruses and Trojans. This data can then be analyzed to determine their vulnerability to attack, efficiency, as well as the risk they present to the confidentiality or availability of the system. Information gathered from a variety of sources may be used in conjunction with each other to derive a more accurate assessment of system vulnerabilities and how to respond to them.