ThomasNet News Logo
Sign Up | Log In | ThomasNet Home | Promote Your Business

NIST's Guide rates software vulnerabilities from misuse.

Print | 
Email |  Comment   Share  
July 30, 2012 - NIST's Common Misuse Scoring System describes scoring system that computer security managers can use to assess severity of security risks arising from software features that, while beneficial to accomplishing task, are at least partially designed under assumption that users are operating these features as intended. CMSS specification allows risk assessment manager to determine vulnerability's potential impact on network and then take remediation steps to secure system.

Software Features and Inherent Risks: NIST's Guide to Rating Software Vulnerabilities from Misuse


National Institute of Standards & Technology
100 Bureau Dr., Stop 1070
Gaithersburg, MD, 20899-1070
USA



Press release date: July 25, 2012

A new guide from the National Institute of Standards and Technology (NIST) describes a "scoring system" that computer security managers can use to assess the severity of security risks arising from software features that, while beneficial to accomplishing a task, are at least partially designed under an assumption that users are operating these features as intended.

NIST's Common Misuse Scoring System (CMSS) provides a systematic way for organizations to determine the severity of software feature misuse-dangerous or illicit email practices, for example-so that the organization can determine how to handle the problem.

"No system is 100 percent secure: every system has vulnerabilities," according to the report. While attention often focuses on software flaws, for example system crashes, software features also introduce vulnerabilities because intentional or accidental misuses of software features have the potential to leak sensitive information, corrupt data, or reduce system availability.

NIST categorizes software vulnerabilities in three general categories. Software flaws-coding errors that allow security breaches-are an obvious problem. Configuration vulnerabilities come from setting the software up improperly-allowing a program access to data it shouldn't see, for instance. But software feature misuse is more subtle. With feature misuse, savvy attackers violate the trust assumptions that are inherent in software features to subvert a system's security.

For example, malicious users may undermine the security of email software. "Two common problems are social engineering and insider threats," explained Karen Scarfone, one of the publication's authors. When users open up a bad email attachment or link, the hackers who sent the email can access the organization's computer network to steal valuable information or bring it down. Malicious users can use email attachments to send out valuable company data or documents to outsiders. Both problems can be very expensive, costing a company money, exposing valuable data and hurting the company's reputation.

The CMSS specification allows the risk assessment manager to determine a vulnerability's potential impact on the network and then take remediation steps to secure the system.

The CMSS specification is designed to work with existing scoring systems developed by NIST to categorize software flaw vulnerabilities* and security configuration issues.**

The new guide, The Common Misuse Scoring System (CMSS): Metrics for Software Feature Misuse Vulnerabilities, (NISTIR 7864) is available at http://csrc.nist.gov/publications/nistir/ir7864/nistir-7864.pdf.

* The Common Vulnerability Scoring System (CVSS) and Its Applicability to Federal Agency Systems (NISTIR 7435) is available at http://csrc.nist.gov/publications/PubsNISTIRs.html.

** The Common Configuration Scoring System (CCSS): Metrics for Software Security Configuration Vulnerabilities (NISTIR 7502) is available at http://csrc.nist.gov/publications/PubsNISTIRs.html.

Media Contact: Evelyn Brown, evelyn.brown@nist.gov, 301-975-5661
Print | 
Email |  Comment   Share  
Contacts: View detailed contact information.


 

Post a comment about this story

Name:
E-mail:
(your e-mail address will not be posted)
Comment title:
Comment:
To submit comment, enter the security code shown below and press 'Post Comment'.
 



 See related product stories
More .....
<!-- PNA - News | PNACON |  18860 -->
Don’t hunt for stories like this.
Let Services
Product News Come to You!
Get a Free Subscription
to Product News Alerts.
-- IMT - News | IMTREG2 |  18716 --
Start Your Free
Subscription to
Industry Market Trends.
 See more product news in:
Services
 More New Product News from this company:
NIST-Sponsored Report addresses greenhouse gas measurement.
Disaster/Failure Study Data will be available via NIST website.
NIST Physicist receives 2011 William F. Meggers Award.
More ....
 Other News from this company:
Five at NIST Honored with Flemming Awards
NIST Fire Protection Engineer Named Service to America Finalist
New Report Identifies Strategies to Achieve Net-Zero Energy Homes
NIST Demonstrates Transfer of Ultraprecise Time Signals over a Wireless Optical Channel
Second Cybersecurity Infrastructure Framework Workshop Gathers May 29-31, 2013
More ....
 Tools for you
Watch Company 
View Company Profile
Company web site
More news from this company
E-Mail Story
Save Story
Search for suppliers of
Trade Associations


Home  |  My ThomasNet News®  |  Industry Market Trends®  |  Submit Release  |  Advertise  |  Contact News  |  About Us
Brought to you by Thomasnet.com        Browse ThomasNet Directory

Copyright © 2013 Thomas Publishing Company. All Rights Reserved.
Terms of Use - Privacy Policy



Error close

Please enter a valid email address