Trust and Risk Assessment Model of Popular Software Based on Known Vulnerabilities

Janiszewski, M; Felkner, A; Olszak, J

  • INTERNATIONAL JOURNAL OF ELECTRONICS AND TELECOMMUNICATIONS;
  • Tom: 63;
  • Numer: 3;
  • Strony: 329-336;
  • 2017;

This paper presents a new concept of an approach to risk assessment which can be done on the basis of publicly available information about vulnerabilities. The presented approach uses also the notion of trust and implements many concepts used in so called trust and reputation management systems (which are widely used in WSN, MANET or P2P networks, but also in ecommerce platforms). The article shows first outcomes obtained from the presented model. The outcomes demonstrate that the model can be implemented in real system to make software management more quantified and objective process, which can have real and beneficial impact on institutional security. In article, however the emphasis was set not on the model itself (which can be easily changed) but on the possibility of finding useful information about vulnerabilities.

Słowa kluczowe: software vulnerabilities, risk assessment, software management, trust and reputation management models, 0-day vulnerabilities forecast, risk of information systems, prediction model