Software features and inherent risks: NIST's guide to rating software vulnerabilities from misuse

Jul 26, 2012

A new guide from the National Institute of Standards and Technology (NIST) describes a "scoring system" that computer security managers can use to assess the severity of security risks arising from software features that, while beneficial to accomplishing a task, are at least partially designed under an assumption that users are operating these features as intended.

NIST's Common Misuse (CMSS) provides a systematic way for organizations to determine the severity of feature misuse—dangerous or illicit email practices, for example—so that the organization can determine how to handle the problem.

"No system is 100 percent secure: every system has vulnerabilities," according to the report. While attention often focuses on software flaws, for example system crashes, software features also introduce vulnerabilities because intentional or accidental misuses of software features have the potential to leak sensitive information, corrupt data, or reduce system availability.

NIST categorizes software vulnerabilities in three general categories. Software flaws—coding errors that allow security breaches—are an obvious problem. Configuration vulnerabilities come from setting the software up improperly—allowing a program access to data it shouldn't see, for instance. But software feature misuse is more subtle. With feature misuse, savvy attackers violate the trust assumptions that are inherent in software features to subvert a system's security.

For example, malicious users may undermine the security of email software. "Two common problems are social engineering and insider threats," explained Karen Scarfone, one of the publication's authors. When users open up a bad email attachment or link, the hackers who sent the email can access the organization's computer network to steal valuable information or bring it down. Malicious users can use email attachments to send out valuable company data or documents to outsiders. Both problems can be very expensive, costing a company money, exposing valuable data and hurting the company's reputation.

The CMSS specification allows the risk assessment manager to determine a vulnerability's potential impact on the network and then take remediation steps to secure the system.

The CMSS specification is designed to work with existing scoring systems developed by NIST to categorize software flaw vulnerabilities* and security configuration issues.**

Explore further: Mozilla lab wants scientists to step out of analog age

More information: The new guide, The Common Misuse Scoring System (CMSS): Metrics for Software Feature Misuse Vulnerabilities, (NISTIR 7864) is available at csrc.nist.gov/publications/nistir/ir7864/nistir-7864.pdf

* The Common Vulnerability Scoring System (CVSS) and Its Applicability to Federal Agency Systems (NISTIR 7435) is available at csrc.nist.gov/publications/PubsNISTIRs.html

** The Common Configuration Scoring System (CCSS): Metrics for Software Security Configuration Vulnerabilities (NISTIR 7502) is available at csrc.nist.gov/publications/PubsNISTIRs.html

add to favorites email to friend print save as pdf

Related Stories

Protecting computers at start-up: New NIST guidelines

Dec 21, 2011

A new draft computer security publication from the National Institute of Standards and Technology (NIST) provides guidance for vendors and security professionals as they work to protect personal computers as they start up.

Recommended for you

Mozilla lab wants scientists to step out of analog age

Jun 18, 2013

(Phys.org) —Talk about big ideas. Not satisfied to rest on laurels of having brought forth the open source browser Firefox, Mozilla—defined by some as a global project, by others as one of the key open-source ...

'Watch Dogs' video game a sign of the times

Jun 17, 2013

Across the dizzying, colorful show floor at last week's Electronic Entertainment Expo, there were games on display where players could become all manner of things, like a throat-slashing 18th century pirate, ...

User comments : 0

More news stories

Multiview 3-D photography made simple

Computational photography is the use of clever light-gathering tricks and sophisticated algorithms to extract more information from the visual environment than traditional cameras can.

Tech companies eye security that goes beyond passwords

In late February, a thief or thieves cracked into Evernote's digital vault filled with log-ins, passwords and email addresses belonging to 50 million users. It was a shocking cyberattack considering the Redwood City, Calif., ...

Danish chemists in molecular chip breakthrough

Electronic components built from single molecules using chemical synthesis could pave the way for smaller, faster and more green and sustainable electronic devices. Now for the first time, a transistor made ...

China astronauts float water blob in kids' lecture

Astronauts struck floating martial arts poses, twirled gyroscopes and manipulated wobbling globes of water during a lecture Thursday from China's orbiting space station that's part of efforts to popularize ...