You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<p>Throughout this guide, the building blocks for <abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr> Based Prioritization have been detailed and analyzed.</p>
5396
5396
<p>Code and analysis is provided for 3 <abbrtitle="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr> Based Prioritization schemes to allow comparison and refinement: </p>
5397
5397
<ol>
5398
-
<li><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Temporal & Threat Metrics (adding Exploitation info per the <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> standard)<ol>
5398
+
<li><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr>v3 Temporal Metric - Exploit Code Maturity (E) (adding Exploitation info per the <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> standard)<ol>
5399
5399
<li>The data from "<ahref="https://github.com/t0sche/cvss-bt">Enriching the <abbrtitle="National Vulnerability Database">NVD</abbr><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores to include Temporal & Threat Metrics</a>" is used here.</li>
At the beginning of the guide it was stated that <ahref="#introduction-introduction-writing-style">the "writing style" in this guide is "succinct and opinionated"</a>.</p>
5418
5418
<p>This section "leads with an opinion", and associated rationale.</p>
5419
5419
</div>
5420
-
<p><spanclass="twemoji"><svgxmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><pathd="m13 18.9 6.1-6.1 2.1 2.1-6.1 6.1H13v-2.1m8.4-7.6 1.3 1.3c.2.2.2.5 0 .7l-1 1-2.1-2 1-1c.1-.1.2-.2.4-.2s.3 0 .4.2M11 21H5c-.5 0-1-.2-1.4-.6-.4-.4-.6-.9-.6-1.4V5c0-.5.2-1 .6-1.4C4 3.2 4.5 3 5 3h14c1.1 0 2 .9 2 2v4h-2V5H5v14h6v2m4-9-5-4v8l5-4Z"/></svg></span><ahref="https://colab.research.google.com/drive/1LOps2ViFbAp5eyC5UG_cr-5bZ8i_4U8B#scrollTo=HHyjMx-Ku7eQ">Colab NoteBook <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base vs <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base & Threat</a></p>
5421
-
<p><imgalt="🧑💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /><ahref="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/cvss-bt.ipynb"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base vs <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base & Threat Source Code</a></p>
5420
+
<p><spanclass="twemoji"><svgxmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><pathd="m13 18.9 6.1-6.1 2.1 2.1-6.1 6.1H13v-2.1m8.4-7.6 1.3 1.3c.2.2.2.5 0 .7l-1 1-2.1-2 1-1c.1-.1.2-.2.4-.2s.3 0 .4.2M11 21H5c-.5 0-1-.2-1.4-.6-.4-.4-.6-.9-.6-1.4V5c0-.5.2-1 .6-1.4C4 3.2 4.5 3 5 3h14c1.1 0 2 .9 2 2v4h-2V5H5v14h6v2m4-9-5-4v8l5-4Z"/></svg></span><ahref="https://colab.research.google.com/drive/1LOps2ViFbAp5eyC5UG_cr-5bZ8i_4U8B#scrollTo=HHyjMx-Ku7eQ">Colab NoteBook <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base vs <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base & Temporal Metric - Exploit Code Maturity/Exploitability (E)</a></p>
5421
+
<p><imgalt="🧑💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /><ahref="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/cvss-bt.ipynb"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base vs <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr>v3 Base & Temporal Metric - Exploit Code Maturity/Exploitability (E) Source Code</a></p>
<h3id="risk-rbp_schemes-cvss-temporal-threat-metrics"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Temporal & Threat Metrics<aclass="headerlink" href="#risk-rbp_schemes-cvss-temporal-threat-metrics" title="Permanent link">¶</a></h3>
5425
-
<p>Exploitation data is added per the <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> standard as described in <ahref="#cvss-cvss-cvss-exploit-maturity"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></a>.</p>
5424
+
<h3id="risk-rbp_schemes-cvss-and-temporal-metric-exploit-code-maturity-e"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr>and Temporal Metric - Exploit Code Maturity (E)<aclass="headerlink" href="#risk-rbp_schemes-cvss-and-temporal-metric-exploit-code-maturity-e" title="Permanent link">¶</a></h3>
5425
+
<p>Exploitation data is added per the <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr>v3 standard as described in <ahref="#cvss-cvss-cvss-exploit-maturity"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></a>.</p>
<figcaption>The effect of CVSS Base & Threat is to move some CVEs down a Rating e.g. some Critical CVEs move to High</figcaption>
5428
+
<figcaption>The effect of CVSS v3 Temporal Metric - Exploit Code Maturity (E) is to move some CVEs down a Rating e.g. some Critical CVEs move to High</figcaption>
5429
5429
</figure>
5430
5430
<h3id="risk-rbp_schemes-cvss-base-score-ratings-with-exploitation-focus"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Score Ratings with Exploitation Focus<aclass="headerlink" href="#risk-rbp_schemes-cvss-base-score-ratings-with-exploitation-focus" title="Permanent link">¶</a></h3>
5431
5431
<p>A simple illustrative scheme that combines Base Score Ratings with Exploitation status is defined here.</p>
<li>The standard <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Temporal & Threat Metrics as described in <ahref="#cvss-cvss-cvss-exploit-maturity"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></a> does not significantly (de)prioritize CVEs.<ol>
5534
+
<li>The standard <abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr>v3 Temporal Metric - Exploit Code Maturity (E) as described in <ahref="#cvss-cvss-cvss-exploit-maturity"><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr></a> does not significantly (de)prioritize CVEs.<ol>
5535
5535
<li>While it uses Exploitation Evidence, it does not <strong>focus on</strong> Exploitation Evidence like the other 2 schemes presented</li>
5536
5536
<li>is based on a standard, but exactly how to use the different types of Exploitation Evidence is not standard or defined</li>
<th><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Temporal & Threat Metrics</th>
5563
+
<th><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr>v3 Temporal Metric - Exploit Code Maturity (E)</th>
5564
5564
<th><abbrtitle="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Score Ratings with Exploitation Focus</th>
0 commit comments