A Model for Android and iOS Applications Risk Calculation: CVSS Analysis and Enhancement Using Case-Control Studies
This work addresses the need for more precise vulnerability risk calculation in mobile applications, which is incremental as it builds on existing CVSS methods.
The paper tackled the problem of inaccurate risk assessment in cybersecurity by proposing improvements to the Common Vulnerability Scoring System (CVSS) for Android and iOS applications, resulting in enhanced accuracy and better focus on key risks for threat intelligence analysts.
Various researchers have shown that the Common Vulnerability Scoring System (CVSS) has many drawbacks and may not provide a precise view of the risks related to software vulnerabilities. However, many threat intelligence platforms and industry-wide standards are relying on CVSS score to evaluate cybersecurity compliance. This paper suggests several improvements to the calculation of Impact and Exploitability sub-scores within the CVSS, improve its accuracy and help threat intelligence analysts to focus on the key risks associated with their assets. We will apply our suggested improvements against risks associated with several Android and iOS applications and discuss achieved improvements and advantages of our modelling, such as the importance and the impact of time on the overall CVSS score calculation.