arXiv:2502.11070cs.CRcs.AI2025-02综述被引 20

系统梳理漏洞优先级评估方法,揭示现有研究短板。

A Survey on Vulnerability Prioritization: Taxonomy, Metrics, and Research Challenges

  • 提出五类指标分类体系:严重性、可利用性、上下文因素等
  • 分析82项研究发现多领域适用性差、动态性不足
  • 适合安全研究人员和企业漏洞管理团队参考

在当今高度互联的数字环境中,由于漏洞数量与复杂性的指数增长,保障复杂基础设施免受网络威胁日益困难。资源限制要求采用有效的漏洞优先级策略,集中精力应对最关键风险。本文对82项相关研究进行了系统性文献综述,提出一种新的分类体系,将度量指标分为严重性、可利用性、上下文因素、预测性指标和聚合方法五类。分析显示现有方法存在显著缺陷,尤其在跨领域适用性方面面临挑战。通过强调动态化、上下文感知的度量指标与可扩展解决方案的重要性,本文为弥合研究与实际应用之间的差距提供了可行见解。该工作通过构建全面的漏洞优先级评估框架,推动了该领域的研究进展,并确立了未来研究方向。

原文摘要 · Abstract (English)

In the highly interconnected digital landscape of today, safeguarding complex infrastructures against cyber threats has become increasingly challenging due to the exponential growth in the number and complexity of vulnerabilities. Resource constraints necessitate effective vulnerability prioritization strategies, focusing efforts on the most critical risks. This paper presents a systematic literature review of 82 studies, introducing a novel taxonomy that categorizes metrics into severity, exploitability, contextual factors, predictive indicators, and aggregation methods. Our analysis reveals significant gaps in existing approaches and challenges with multi-domain applicability. By emphasizing the need for dynamic, context-aware metrics and scalable solutions, we provide actionable insights to bridge the gap between research and real-world applications. This work contributes to the field by offering a comprehensive framework for evaluating vulnerability prioritization methodologies and setting a research agenda to advance the state of practice.

漏洞评估安全研究优先级排序

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。