arrow
Return

A Survey on Software Vulnerability Exploitability Assessment

delete2024-04-26
delete2
delete
OA
AI
S
Sarah Elder *
M
Md Rayhanur Rahman
G
Gage Fringer
K
Kunal Kapoor
L
Laurie Williams
DOI:10.1145/3648610delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Knowing the exploitability and severity of software vulnerabilities helps practitioners prioritize vulnerability mitigation efforts. Researchers have proposed and evaluated many different exploitability assessment methods. The goal of this research is to assist practitioners and researchers in understanding existing methods for assessing vulnerability exploitability through a survey of exploitability assessment literature. We identify three exploitability assessment approaches: assessments based on original, manual Common Vulnerability Scoring System, automated Deterministic assessments, and automated Probabilistic assessments. Other than the original Common Vulnerability Scoring System, the two most common sub-categories are Deterministic, Program State based, and Probabilistic learning model assessments.
Keywords:
Exploitability
software vulnerability

Journal

ACM Computing Surveys cover
ACM Computing Surveys
IF:
28
Papers:
2.4K
Citations:
3.5W

Organization

N
North Carolina State University
Scholars:
2.6W
Papers: 2.3W
Citations: 3.7W