Skip to main content
QUICK REVIEW

[论文解读] The Effect of Security Education and Expertise on Security Assessments: the Case of Software Vulnerabilities

Luca Allodi, Marco Cremonini|arXiv (Cornell University)|Aug 20, 2018
Information and Cyber Security参考文献 39被引用 5
一句话总结

本研究探讨了安全教育与专业专长如何影响基于CVSS v3框架的软件漏洞严重性评估的准确性。研究发现,个体技能组合——尤其是实践知识与系统意识——比正式教育或工作经验更为重要,当技术、操作和用户视角的专长与培训达到平衡时,其评估质量与专业经验相当。

ABSTRACT

In spite of the growing importance of software security and the industry demand for more cyber security expertise in the workforce, the effect of security education and experience on the ability to assess complex software security problems has only been recently investigated. As proxy for the full range of software security skills, we considered the problem of assessing the severity of software vulnerabilities by means of a structured analysis methodology widely used in industry (i.e. the Common Vulnerability Scoring System (\CVSS) v3), and designed a study to compare how accurately individuals with background in information technology but different professional experience and education in cyber security are able to assess the severity of software vulnerabilities. Our results provide some structural insights into the complex relationship between education or experience of assessors and the quality of their assessments. In particular we find that individual characteristics matter more than professional experience or formal education; apparently it is the \emph{combination} of skills that one owns (including the actual knowledge of the system under study), rather than the specialization or the years of experience, to influence more the assessment quality. Similarly, we find that the overall advantage given by professional expertise significantly depends on the composition of the individual security skills as well as on the available information.

研究动机与目标

  • 理解安全教育与专业经验如何影响现实情境中漏洞严重性评估的质量。
  • 评估正式教育与专业经验在使用标准化CVSS v3框架时,哪一种能带来更准确的评估结果。
  • 研究个体技能组合(如技术知识、系统意识和用户视角)在塑造评估结果中的作用。
  • 评估专业专长是否可以替代正式教育,反之亦然,以实现高质量的安全评估。
  • 探讨漏洞描述模糊性对评估准确性及不确定性下的决策影响。

提出的方法

  • 开展一项受控实验,参与者分为三组:接受过安全教育的学生、未接受过此类教育的学生,以及拥有工作经验但无正式安全教育的专业人士。
  • 参与者使用CVSS v3评分系统对一组软件漏洞进行评估,遵循标准化指南和统一的入门讲座。
  • 以CVSS v3指标(如攻击向量、用户交互)作为客观参照点,评估评估的准确性和一致性。
  • 应用统计分析比较各组间评分的方差,并评估个体特征对评估质量的影响。
  • 通过固定漏洞序列和组内方差分析,控制评估顺序和学习效应等混杂因素。
  • 通过纳入专业人士并承认基于学生样本的局限性及漏洞描述中缺少上下文信息的问题,缓解外部效度的担忧。

实验结果

研究问题

  • RQ1与专业经验相比,正式安全教育是否能带来更准确的漏洞严重性评估?
  • RQ2个体技能组合(如技术知识、系统意识和用户视角)如何影响评估质量?
  • RQ3专业经验在多大程度上可弥补缺乏正式教育在漏洞评估任务中的不足?
  • RQ4漏洞描述的模糊性如何影响评估的一致性与准确性?
  • RQ5特定培训在多大程度上可替代多年经验,以实现高质量的漏洞评估?

主要发现

  • 实践知识与系统意识等个体特征对评估质量的影响,显著超过正式教育或工作年限。
  • 工作年限与评估准确性之间并无强相关性;事实上,某些情况下观察到负相关。
  • 技术、操作和用户导向等多样化安全技能的组合,比任何单一因素更能预测评估质量。
  • 专业专长仅在与全面的技能组合及完整信息获取相结合时,才具有显著优势。
  • 当正式教育与专业经验共同促进平衡且整合的技能组合时,两者可产生相当的评估质量。
  • 由于缺乏真实情境信息,本研究的准确性估计较为保守,表明实际专业表现可能更高。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。