Skip to content

Commit 8c28a37

Browse files
committed
Deployed 5f8fe0e with MkDocs version: 1.5.3
1 parent 72a8f0f commit 8c28a37

15 files changed

Lines changed: 80 additions & 54 deletions

File tree

cvss/CVSS/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1420,7 +1420,7 @@ <h1 id="common-vulnerability-scoring-system-cvss">Common Vulnerability Scoring S
14201420
<li><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Severity Rating</li>
14211421
<li><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Confidentiality, Integrity, Availability Impacts</li>
14221422
</ul>
1423-
<p><img alt="🧑‍💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /> <a href="https://github.com/epss-sig/epss-interoperability/blob/main/analysis/cisa_kev_epss_cvss.ipynb">Source Code</a> </p>
1423+
<p><img alt="🧑‍💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /> <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/cisa_kev_epss_cvss.ipynb">Source Code</a> </p>
14241424
</div>
14251425
<h2 id="cvss-severity-rating-scale"><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Severity Rating Scale<a class="headerlink" href="#cvss-severity-rating-scale" title="Permanent link">&para;</a></h2>
14261426
<div class="admonition quote">

introduction/Introduction/index.html

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1528,8 +1528,9 @@ <h2 id="writing-style">Writing Style<a class="headerlink" href="#writing-style"
15281528
</div>
15291529
<h2 id="source-code">Source Code<a class="headerlink" href="#source-code" title="Permanent link">&para;</a></h2>
15301530
<ol>
1531-
<li>See <a href="https://github.com/epss-sig/epss-interoperability">https://github.com/epss-sig/epss-interoperability</a> TODO
1532-
for the code<ol>
1531+
<li>
1532+
<p><img alt="🧑‍💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /> See <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/">Source Code</a> for the code</p>
1533+
<ol>
15331534
<li>This includes the data used in the analysis (downloaded
15341535
Jan 13) and how to download it</li>
15351536
</ol>

introduction/code_and_data/index.html

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1644,30 +1644,30 @@ <h2 id="data-sources">Data Sources<a class="headerlink" href="#data-sources" tit
16441644
</tbody>
16451645
</table>
16461646
<h2 id="analysis">Analysis<a class="headerlink" href="#analysis" title="Permanent link">&para;</a></h2>
1647-
<p>See <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/analysis">analysis</a> directory for these files.</p>
1647+
<p>See <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/tree/main/analysis">analysis</a> directory for these files.</p>
16481648
<ol>
1649-
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/analysis/enrich_cves.ipynb">enrich_cves.ipynb</a> <ol>
1650-
<li>Take the data sources from <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/data_in/">data_in/</a> </li>
1649+
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/enrich_cves.ipynb">enrich_cves.ipynb</a> <ol>
1650+
<li>Take the data sources from <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/tree/main/data_in/">data_in/</a> </li>
16511651
<li>Enrich the <abbr title="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> data from <abbr title="National Vulnerability Database">NVD</abbr> with the other data sources</li>
16521652
<li>Add an "Exploit" column to indicate the source of the exploitability (used later to set colors of <abbr title="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> data in plots)</li>
16531653
<li>store the output in data_out/nvd_cves_v3_enriched.csv.gz</li>
16541654
</ol>
16551655
</li>
1656-
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/analysis/kev_epss_cvss.ipynb">kev_epss_cvss.ipynb</a><ol>
1656+
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/cisa_kev_epss_cvss.ipynb">kev_epss_cvss.ipynb</a><ol>
16571657
<li>Read the enriched <abbr title="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> data from data_out/CVSSData_enriched.csv.gz</li>
16581658
<li>Read the data from <abbr title="Cybersecurity &amp; Infrastructure Security Agency">CISA</abbr> <abbr title="Known Exploited Vulnerability">KEV</abbr> alert reports in ./data_in/cisa_kev/</li>
16591659
<li>Plot <abbr title="Cybersecurity &amp; Infrastructure Security Agency">CISA</abbr> <abbr title="Known Exploited Vulnerability">KEV</abbr> datasets showing <abbr title="Exploit Prediction Scoring System">EPSS</abbr>, <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> by source of the exploitability</li>
16601660
<li>Write data_out/cisa_kev/csa/csa.csv.gz which is the <abbr title="Cybersecurity &amp; Infrastructure Security Agency">CISA</abbr> <abbr title="Known Exploited Vulnerability">KEV</abbr> CyberSecurity Alerts (CSA) subset with <abbr title="Exploit Prediction Scoring System">EPSS</abbr> and other data</li>
16611661
</ol>
16621662
</li>
1663-
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/qualys.ipynb">qualys.ipynb</a><ol>
1663+
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/qualys.ipynb">qualys.ipynb</a><ol>
16641664
<li>Read the enriched <abbr title="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> data from data_out/CVSSData_enriched.csv.gz</li>
16651665
<li>Read the data from ./data_in/qualys</li>
16661666
<li>Plot Qualys dataset showing <abbr title="Exploit Prediction Scoring System">EPSS</abbr>, <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> by source of the exploitability</li>
16671667
<li>Write data_out/qualys/qualys.csv.gz which is the Qualys data with <abbr title="Exploit Prediction Scoring System">EPSS</abbr> and other data</li>
16681668
</ol>
16691669
</li>
1670-
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/msrc.ipynb">msrc.ipynb</a><ol>
1670+
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/msrc.ipynb">msrc.ipynb</a><ol>
16711671
<li>Read the enriched <abbr title="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> data from data_out/CVSSData_enriched.csv.gz</li>
16721672
<li>Read the data from ./data_in/msrc</li>
16731673
<li>Plot Microsoft Exploitability Index dataset showing <abbr title="Exploit Prediction Scoring System">EPSS</abbr>, <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> by source of the exploitability</li>
@@ -1676,9 +1676,9 @@ <h2 id="analysis">Analysis<a class="headerlink" href="#analysis" title="Permanen
16761676
</li>
16771677
</ol>
16781678
<h3 id="cisa-ssvc-decision-trees"><abbr title="Cybersecurity &amp; Infrastructure Security Agency">CISA</abbr> <abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr> Decision Trees<a class="headerlink" href="#cisa-ssvc-decision-trees" title="Permanent link">&para;</a></h3>
1679-
<p>See <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/cisa_ssvc_dt/">cisa_ssvc_dt</a> directory for these files.</p>
1679+
<p>See <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/tree/main/cisa_ssvc_dt/">cisa_ssvc_dt</a> directory for these files.</p>
16801680
<h4 id="cisa-ssvc-decision-tree-from-scratch-example-implementation"><abbr title="Cybersecurity &amp; Infrastructure Security Agency">CISA</abbr> <abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr> Decision Tree From Scratch Example Implementation<a class="headerlink" href="#cisa-ssvc-decision-tree-from-scratch-example-implementation" title="Permanent link">&para;</a></h4>
1681-
<p><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/cisa_ssvc_dt/DT_from_scratch.ipynb">DT_from_scratch.ipynb</a> </p>
1681+
<p><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/tree/main/cisa_ssvc_dt/DT_from_scratch.ipynb">DT_from_scratch.ipynb</a> </p>
16821682
<ol>
16831683
<li>Read the enriched <abbr title="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr> data from data_out/CVSSData_enriched.csv.gz</li>
16841684
<li>Read the Decision Tree definition cisa_ssvc_dt/DT_rbp.csv</li>
@@ -1694,7 +1694,7 @@ <h4 id="cisa-ssvc-decision-tree-from-scratch-example-implementation"><abbr title
16941694
<li>Plot </li>
16951695
</ol>
16961696
<h4 id="cisa-ssvc-decision-tree-analysis-for-feature-importance"><abbr title="Cybersecurity &amp; Infrastructure Security Agency">CISA</abbr> <abbr title="SSVC Stakeholder-Specific Vulnerability Categorization">SSVC</abbr> Decision Tree Analysis for Feature Importance<a class="headerlink" href="#cisa-ssvc-decision-tree-analysis-for-feature-importance" title="Permanent link">&para;</a></h4>
1697-
<p><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/cisa_ssvc_dt/DT_analysis.ipynb">DT_analysis.ipynb</a> </p>
1697+
<p><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/tree/main/cisa_ssvc_dt/DT_analysis.ipynb">DT_analysis.ipynb</a> </p>
16981698
<ol>
16991699
<li>Read the Decision Tree definition cisa_ssvc_dt/DT_rbp.csv</li>
17001700
<li>Perform Feature Importance using 2 methods</li>
@@ -1705,14 +1705,14 @@ <h4 id="cisa-ssvc-decision-tree-analysis-for-feature-importance"><abbr title="Cy
17051705
<h2 id="getting-data-from-data-sources">Getting Data from Data Sources<a class="headerlink" href="#getting-data-from-data-sources" title="Permanent link">&para;</a></h2>
17061706
<div class="admonition tip">
17071707
<p class="admonition-title">A snapshot of the data used for this guide is available</p>
1708-
<p>A snapshot of this data is already available with the source in <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/data_in">data_in</a></p>
1708+
<p>A snapshot of this data is already available with the source in <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/tree/main/data_in">data_in</a></p>
17091709
<ul>
17101710
<li>A date.txt file is included in each folder with the data that contains the date of download.</li>
17111711
</ul>
17121712
<p>But you can download current data as described here. </p>
17131713
</div>
17141714
<ul>
1715-
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/data/get_data.sh">get_data.sh</a> gets the data that can be downloaded automatically and used as-is.</li>
1715+
<li><a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/tree/main/data/get_data.sh">get_data.sh</a> gets the data that can be downloaded automatically and used as-is.</li>
17161716
<li>Other data is manually downloaded - see instructions below.<ul>
17171717
<li>MSRC</li>
17181718
<li>ExploitDB</li>
@@ -1724,7 +1724,7 @@ <h2 id="getting-data-from-data-sources">Getting Data from Data Sources<a class="
17241724
<h3 id="national-vulnerability-database-nvd">National Vulnerability Database (<abbr title="National Vulnerability Database">NVD</abbr>)<a class="headerlink" href="#national-vulnerability-database-nvd" title="Permanent link">&para;</a></h3>
17251725
<p>Get <abbr title="National Vulnerability Database">NVD</abbr> data automatically</p>
17261726
<ul>
1727-
<li>A notebook or script in <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/data_in/nvd">nvd</a> downloads the <abbr title="National Vulnerability Database">NVD</abbr> data.</li>
1727+
<li>A notebook or script in <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/tree/main/data_in/nvd">nvd</a> downloads the <abbr title="National Vulnerability Database">NVD</abbr> data.</li>
17281728
<li>The data is output to data_out/CVSSData.csv.gz</li>
17291729
<li>Note: The download method used will be deprecated some time after Dec 2023 per <a href="https://nvd.nist.gov/vuln/data-feeds">https://nvd.nist.gov/vuln/data-feeds</a></li>
17301730
</ul>

0 commit comments

Comments
 (0)