Projects per year
Abstract
Using the Kolmogorov–Smirnov, Cramér–von Mises and Anderson–Darling tests, and the not so commonly applied Vuong’s test, it is shown that a two components hyperlog-logistic distribution, i.e., a mixture of two geo-max-stable log-logistic distributions, provides a good fit for the time from disclosure to update of vulnerabilities sampled from the CVEdetails.com database. It is also shown that the hyperlog-logistic distribution provides a better fit than a heavy-tailed distribution of maxima, or a log-logistic distribution, or even a heavy-tailed two components hyperexponential distribution. Moreover, ways of incorporating uncertainty and of modeling vulnerabilities lifecycle into the Common Vulnerabilities Scoring System (CVSS), the most widely used score to assess severity of vulnerabilities, are discussed, in order to obtain an improved CVSS calculator and the evolution of a score over time.
Original language | English |
---|---|
Title of host publication | New frontiers in statistics and data science |
Subtitle of host publication | SPE2023 |
Editors | Lígia Henriques-Rodrigues, Raquel Menezes, Luís Meira Machado, Susana Faria, Miguel de Carvalho |
Publisher | Springer |
Pages | 69-82 |
Number of pages | 14 |
Edition | 1 |
ISBN (Electronic) | 9783031689499 |
ISBN (Print) | 9783031689482, 9783031726071 |
DOIs | |
Publication status | Published - Jan 2025 |
Event | 26th Congress of the Portuguese Statistical Society, SPE 2023 - Evora, Portugal Duration: 13 Oct 2021 → 16 Oct 2021 |
Publication series
Name | Springer Proceedings in Mathematics and Statistics |
---|---|
ISSN (Print) | 2194-1009 |
ISSN (Electronic) | 2194-1017 |
Conference
Conference | 26th Congress of the Portuguese Statistical Society, SPE 2023 |
---|---|
Country/Territory | Portugal |
City | Evora |
Period | 13/10/21 → 16/10/21 |
Keywords
- CVSS modifier
- Heavy-tailed distributions
- Hyperlog-logistic distribution
- Vulnerabilities
- Vulnerabilities lifecycle
Fingerprint
Dive into the research topics of 'Risk assessment of vulnerabilities exploitation'. Together they form a unique fingerprint.Projects
- 1 Active
-
CITAR: Research Center for Science and Technology of the Arts
Vieira, E. (PI), Nobre da Silva Pais, A. M. (Other career/Public sector), Filipe, C. (Private Sector), Serra, S. (Assistant Professor), Baltazar, A. (Assistant Professor), Lobo, C. (Invited Assistant Professor), Carmona, C. R. (Assistant Professor), Sá, C. (Assistant Professor), Sousa, G. V. E. (Full Professor), Pereira, H. M. (Assistant Professor), Neves, J. (Invited Assistant Professor), Teixeira, J. (Invited Assistant Professor), Gomes, J. A. (Invited Assistant Professor), Carvalho, J. V. (Invited Assistant Professor), Castro, L. (Assistant Professor), Teixeira, L. (Assistant Professor), Aguiar, M. (Assistant Professor), Crespo, N. (Assistant Professor), Camarneiro, N. (Invited Assistant Professor), Costa, P. R. (Invited Assistant Professor), Pestana, P. D. (Invited Assistant Professor), Alves, P. (Invited Assistant Professor), Kunz, S. (Assistant Professor), Neves, S. (Invited Assistant Professor), Coutinho, V. M. (Invited Assistant Professor), Galán-Pérez, A. (Private Sector), Rangel, A. (Professor non-higher education), Natálio, C. (Researcher), Henriques, F. (Researcher), Afonso Lopes, M. I. (Private Sector), Bordalo, R. (Researcher) & Lammeren, S. R. L. V. (Researcher)
1/01/20 → 31/12/25
Project: Research