Vulnerability severity scoring and bounties: why the disconnect?

Author:

Munaiah Nuthan1,Meneely Andrew1

Affiliation:

1. Rochester Institute of Technology, USA

Publisher

ACM

Reference31 articles.

1. Coders’ Rights Project Vulnerability Reporting FAQ. https://www.eff.org/issues/coders/ vulnerability-reporting-faq. Accessed: 2016-04-03. Coders’ Rights Project Vulnerability Reporting FAQ. https://www.eff.org/issues/coders/ vulnerability-reporting-faq. Accessed: 2016-04-03.

2. Common Vulnerability Scoring System (CVSS-SIG). https://www.first.org/cvss. Accessed: 2016-03-12. Common Vulnerability Scoring System (CVSS-SIG). https://www.first.org/cvss. Accessed: 2016-03-12.

3. Severity Ratings - Red Hat Customer Portal. https://access.redhat.com/security/updates/ classification. Accessed: 2016-08-14. Severity Ratings - Red Hat Customer Portal. https://access.redhat.com/security/updates/ classification. Accessed: 2016-08-14.

4. IEEE Standard Classification for Software Anomalies. IEEE Std 1044-2009 (Revision of IEEE Std 1044-1993) pages 1–25 Jan 2010. IEEE Standard Classification for Software Anomalies. IEEE Std 1044-2009 (Revision of IEEE Std 1044-1993) pages 1–25 Jan 2010.

5. Software Vulnerability Markets: Discoverers and Buyers. Int. Journal Computer, Information;Algarni A.;Systems and Control Engineering,2014

Cited by 22 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Reputation Gaming in Crowd Technical Knowledge Sharing;ACM Transactions on Software Engineering and Methodology;2024-09-04

2. Methodological Advancements in Standardizing Blockchain Assessment;IEEE Access;2024

3. Merchants of Vulnerabilities: How Bug Bounty Programs Benefit Software Vendors;SSRN Electronic Journal;2024

4. NUVER: Network Based Vulnerability Visualizer;2023 IEEE 30th Annual Software Technology Conference (STC);2023-09-25

5. Software Development Analytics in Practice: A Systematic Literature Review;Archives of Computational Methods in Engineering;2023-01-10

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3