Abstract

The information technology level of China continues to improve, and various industries are digitalized in different degrees. However, the development of the network has correspondingly brought the trouble of loopholes, which have caused mass economic losses to many enterprises. In the era of big data, it is necessary to understand the characteristics of the ever-emerging vulnerabilities. In this study, we used descriptive statistics and programming techniques to analyze more than 140,000 vulnerability records from CVE and CNNVD. We visualize the development trend of vulnerabilities through descriptive statistics and summarized the characteristics of vulnerabilities in products from manufacturers of different scales. The result shows that large companies usually face more and severer loopholes. Then, multivariate regression is conducted to explore the relationship between vulnerability type, threat type and hazard level. K-means clustering method is employed to select and extract features based on the description paragraphs of vulnerabilities. Finally, we categorize the loopholes according to different patterns, so as to find a breakthrough point for a quicker solution to new vulnerabilities with the existing classified database. The combined sources are proved to be useful for clustering analysis.

Details

Title
Combining sources from CVE and CNNVD: Data analysis in information security vulnerabilities
Author
Jin, Ruiying 1 ; Jing, Nan 2 

 School of Economics and Management, Beijing Jiaotong University, Beijing, 100000, China 
 School of Computer, Beijing Jiaotong University, Beijing, 100000, China 
Publication year
2021
Publication date
Feb 2021
Publisher
IOP Publishing
ISSN
17426588
e-ISSN
17426596
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
2512952724
Copyright
© 2021. This work is published under http://creativecommons.org/licenses/by/3.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.