🤖 AI Summary
This study addresses the limitation of existing vulnerability scoring research, which predominantly focuses on statistical correlations while neglecting the practical impact on system-level risk modeling. From an operational consequence perspective, this work presents the first empirical comparative analysis of four mainstream vulnerability scoring systems, including CVSS, within a realistic Operational Technology (OT) network scenario reconstructed from the 2015 Ukrainian power grid topology. The findings reveal significant discrepancies among these systems regarding patch prioritization, demonstrating that reliance on any single scoring metric can severely misguide mitigation strategies. Accordingly, this paper advocates for the adoption of hybrid scoring methodologies, establishing a novel quantitative assessment paradigm for vulnerability risk management in critical infrastructure.
📝 Abstract
Vulnerability scoring systems underpin cyber patch prioritization and risk management, but their comparative behavior is almost always assessed in the abstract, through correlation studies in IT vulnerability databases, rather than by the operational consequences they produce when embedded in a system-level risk model. Here we present an empirical comparison of four vulnerability scoring systems, namely CVSS (Common Vulnerability Scoring System), EPSS (Exploit Prediction Scoring System), SSVC (Stakeholder-Specific-Vulnerability Categorization), and IronMiner (operationally calibrated proprietary scoring system). As a substrate for comparison, we use a reconstruction of the 2015 Ukraine Power Grid operational-technology (OT) network that provides a documented incident topology. The results show a high degree of disagreement between the scoring systems. This suggests that the choice of the scoring system could significantly influence mitigation strategies and vulnerability prioritization, implying that a composite or hybrid scoring approach could offer a more suitable solution.