Towards System Security: What a Comparison of National Vulnerability Databases Reveals


연구 분야: Databases



학회: 2022 17th Iberian Conference on Information Systems and Technologies (CISTI)


초록

System vulnerabilities are ubiquitous nowadays. In 2021, millions of cyberattacks exploited system flaws resulting in billions of losses. Despite massive vulnerability databases supported by the USA and China governments, there are still several unknown issues between them. This paper proposes a methodology to compare the National Vulnerability Database (NVD), the China National Vulnerability Database (CNVD), and the China National Vulnerability Database of Information Security (CNNVD). The results reveal that the CNNVD has 1,661 vulnerabilities entries more than the NVD and at least 40 more entries regarding Chinese vendors. Moreover, there is a temporal correlation of 0.917560 between the NVD and CNNVD. To the best of the authors’ knowledge, this work is the first to normalize and compare the NVD, CNVD, and CNNVD using their data feeds.


Author Profile
Igor Forain

Electrical Engineering Department Professional Post-Graduation Program in Electrical Engineering - PPEE Faculty of Technology University of Brasília (UnB) Brasília Brazil

Brazil
Author Profile
Robson de Oliveira Albuquerque

Electrical Engineering Department Professional Post-Graduation Program in Electrical Engineering - PPEE Faculty of Technology University of Brasília (UnB) Brasília Brazil

Brazil
Author Profile
Rafael Timóteo de Sousa Júnior

Electrical Engineering Department Professional Post-Graduation Program in Electrical Engineering - PPEE Faculty of Technology University of Brasília (UnB) Brasília Brazil

Brazil

📄 논문 정보

발행 연도 2022년
인용수 5
출판 국가 Brazil
사이트 IEEE
좋아요 수 0

연관 논문 목록 (21건)