The Effect of Security Education and Expertise on Security Assessments: the Case of Software Vulnerabilities

08/20/2018
by   Luca Allodi, et al.
0

In spite of the growing importance of software security and the industry demand for more cyber security expertise in the workforce, the effect of security education and experience on the ability to assess complex software security problems has only been recently investigated. As proxy for the full range of software security skills, we considered the problem of assessing the severity of software vulnerabilities by means of a structured analysis methodology widely used in industry (i.e. the Common Vulnerability Scoring System () v3), and designed a study to compare how accurately individuals with background in information technology but different professional experience and education in cyber security are able to assess the severity of software vulnerabilities. Our results provide some structural insights into the complex relationship between education or experience of assessors and the quality of their assessments. In particular we find that individual characteristics matter more than professional experience or formal education; apparently it is the combination of skills that one owns (including the actual knowledge of the system under study), rather than the specialization or the years of experience, to influence more the assessment quality. Similarly, we find that the overall advantage given by professional expertise significantly depends on the composition of the individual security skills as well as on the available information.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/14/2023

The Future of Cybersecurity in Southeast Asia along the Maritime Silk Road

This paper proposes an analysis of the prospects of the cyber security i...
research
04/13/2023

Rule-based detection of access to education and training in Germany

As a result of transformation processes, the German labor market is high...
research
01/06/2021

Design of Secure Coding Challenges for Cybersecurity Education in the Industry

According to a recent survey with more than 4000 software developers, le...
research
03/27/2023

The Gap between Higher Education and the Software Industry – A Case Study on Technology Differences

We see an explosive global labour demand in the Software Industry, and h...
research
08/09/2017

Success Criteria For Implementing Technology in Special Education: a Case Study

The Kingdom of Saudi Arabia (KSA) has made a large investment in deployi...
research
10/09/2021

Emergent Insight of the Cyber Security Management for Saudi Arabian Universities: A Content Analysis

While cyber security has become a prominent concept of emerging informat...
research
06/05/2019

Updating the Wassenaar Debate Once Again: Surveillance, Intrusion Software, and Ambiguity

This paper analyzes a recent debate on regulating cyber weapons through ...

Please sign up or login with your details

Forgot password? Click here to reset