{"id":"W3130519220","doi":"10.1109/trustcom50675.2020.00067","title":"Evaluating the Soundness of Security Metrics from Vulnerability Scoring Frameworks","year":2020,"lang":"en","type":"article","venue":"","topic":"Software Reliability and Analysis Research","field":"Computer Science","cited_by":6,"is_retracted":false,"has_abstract":true,"ca_institutions":"Carleton University","funders":"Natural Sciences and Engineering Research Council of Canada","keywords":"Soundness; Computer science; Software security assurance; Vulnerability (computing); Secure coding; Context (archaeology); Vulnerability assessment; Computer security; Vulnerability management; Software; Security information and event management; Information security; Risk analysis (engineering); Security service; Cloud computing security; Business","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":["metaresearch"],"consensus_categories":[],"category_scores_codex":[0.1054609,0.002888091,0.001420692,0.01840516,0.001651974,0.005347812,0.002923572,0.002998057,0.0009597263],"category_scores_gemma":[0.3914976,0.0008073939,0.001576415,0.008307132,0.003092597,0.00707623,0.005592176,0.002837044,0.0002856165],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.00420205,"about_ca_system_score_gemma":0.007322955,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.007004853,"about_ca_topic_score_gemma":0.007427255,"domain_scores_codex":[0.8491362,0.05599591,0.01509942,0.005191699,0.07162154,0.002955331],"domain_scores_gemma":[0.6127144,0.2469554,0.03376638,0.0322606,0.07093126,0.003372019],"domain_codex":null,"domain_gemma":"evaluation","domain_candidate":"evaluation","domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"not_applicable","study_design_scores_codex":[0.001221671,0.001102724,0.2018355,0.002267708,0.001037835,0.0005119239,0.003107755,0.2288614,0.01672657,0.05929912,0.004364507,0.4796633],"study_design_scores_gemma":[0.0002867007,0.00350555,0.07228099,0.001590751,0.0005086398,0.000694634,0.002103961,0.8168361,0.02985606,0.06111076,0.01075821,0.0004676829],"study_design_candidate":"not_applicable","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.4996139,0.003229246,0.4817733,0.00197217,0.0003130497,0.001639592,0.001312877,0.002167203,0.007978639],"genre_scores_gemma":[0.6470454,0.0006376742,0.349301,0.0001358991,0.00005100617,0.0006979108,0.001570131,0.000208532,0.0003524066],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.8945391,"threshold_uncertainty_score":0.5577371,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.1286683248139874,"score_gpt":0.3999609885309979,"score_spread":0.2712926637170105,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}