3 ms·
Might be worth reading this article : https://media.blackhat.com/us-13/US-13-Martin-Buying-Into-The-Bias-Why-Vulnerability-Statistics-Suck-WP.pdf https://media
by sseth 9y ago
Might be worth reading this article :
https://media.blackhat.com/us-13/US-13-Martin-Buying-Into-The-Bias-Why-Vulnerability-Statistics-Suck-WP.pdf https://media.blackhat.com/us-13/US-13-Martin-Buying-Into-Th...
It is really pointless using the count of CVEs as a measure of how vulnerable a product is.
- ksk 9y agoAFAIK, every single form of aggregation that reduces variance, biases your data set. >It is really pointless using the count of CVEs as a measure of how vulnerable a product is. I read the article, and that is certainly the opinion of the author here. Security is a large field. You can reduce it to number of bugs. You can reduce it to the development process used to create the product. You can reduce it to methods of defending against future vulnerabilities. You can reduce it to methods of tackling bugs. You can reduce it in along any axis. I don't think using CVEs as a measure is pointless. I find them to be useful.