는 오랫동안 검증된 취약점 평가 체계로 웹에서 무료로 얻을 수 있고 문서화가 잘 되어 있다.
CVSS
는 범용 취약점 평가 체계를 의도하여 모든 종류의 시스템에 적합한 것은 아니며 드물게
나타나거나 연쇄적인 취약점을 정확히 평가하지는 못한다는 비판을 받기도 한다. 하지만 공통
적인(
OWASP
상위
10
개) 취약점에 대한 범용 취약점 채점에 사용하기에 적합한 공개 취약점
평가 프레임워크다.
책을 쓰는 시점의
CVSS
시스템의 버전은
3
.
1
이며 채점 항목은 다음 세 가지로 분류된다.
●
기본 점수
base
score
: 취약점 자체를 평가
●
임시 점수
temporal
score
: 시간에 따른 취약점의 심각도를 채점
●
환경 점수
environmental
score
: 취약점이 존재하는 환경에 근거하여 채점
292
3
부
방어
그중
CVSS
기본 점수가 가장 널리 사용되며 임시 점수와 환경 점수는 좀 더 자세한 평가에 사
용된다. 채점 방식을 하나씩 살펴보자.
21.3.1 ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month, and much more.
O’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
I wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
I’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
I'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.