Skip to main navigation Skip to search Skip to main content

An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources

  • Roland Croft
  • , M. Ali Babar
  • , Li Li
  • University of Adelaide
  • Cyber Security Cooperative Research Centre
  • Monash University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Software Vulnerability (SV) severity assessment is a vital task for informing SV remediation and triage. Ranking of SV severity scores is often used to advise prioritization of patching efforts. However, severity assessment is a difficult and subjective manual task that relies on expertise, knowledge, and standardized reporting schemes. Consequently, different data sources that perform independent analysis may provide conflicting severity rankings. Inconsistency across these data sources affects the reliability of severity assessment data, and can consequently impact SV prioritization and fixing. In this study, we investigate severity ranking inconsistencies over the SV reporting lifecycle. Our analysis helps characterize the nature of this problem, identify correlated factors, and determine the impacts of inconsistency on downstream tasks. Our findings observe that SV severity often lacks consideration or is underestimated during initial reporting, and such SVs consequently receive lower prioritization. We identify six potential attributes that are correlated to this misjudgment, and show that inconsistency in severity reporting schemes can severely degrade the performance of downstream severity prediction by up to 77%. Our findings help raise awareness of SV severity data inconsistencies and draw attention to this data quality problem. These insights can help developers better consider SV severity data sources, and improve the reliability of consequent SV prioritization. Furthermore, we encourage researchers to provide more attention to SV severity data selection.

Original languageEnglish
Title of host publicationProceedings - 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering, SANER 2022
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages338-348
Number of pages11
ISBN (Electronic)9781665437868
DOIs
StatePublished - 2022
Externally publishedYes
Event29th IEEE International Conference on Software Analysis, Evolution and Reengineering, SANER 2022 - Virtual, Online, United States
Duration: 15 Mar 202218 Mar 2022

Publication series

NameProceedings - 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering, SANER 2022

Conference

Conference29th IEEE International Conference on Software Analysis, Evolution and Reengineering, SANER 2022
Country/TerritoryUnited States
CityVirtual, Online
Period15/03/2218/03/22

Keywords

  • data quality
  • severity assessment
  • software vulnerability

Fingerprint

Dive into the research topics of 'An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources'. Together they form a unique fingerprint.

Cite this