Skip to content

Commit f7edaae

Browse files
committed
Deployed 4c1adf1 with MkDocs version: 1.5.3
1 parent 9ea4043 commit f7edaae

6 files changed

Lines changed: 123 additions & 105 deletions

File tree

assets/images/cvss_b_bt.png

95.3 KB
Loading

cvss/CVSS/index.html

Lines changed: 52 additions & 43 deletions
Original file line numberDiff line numberDiff line change
@@ -658,15 +658,6 @@
658658
</span>
659659
</a>
660660

661-
</li>
662-
663-
<li class="md-nav__item">
664-
<a href="#count-of-cves-at-or-above-cvss-base-score" class="md-nav__link">
665-
<span class="md-ellipsis">
666-
Count of CVEs at or above CVSS Base Score
667-
</span>
668-
</a>
669-
670661
</li>
671662

672663
<li class="md-nav__item">
@@ -686,6 +677,15 @@
686677
</span>
687678
</a>
688679

680+
</li>
681+
682+
<li class="md-nav__item">
683+
<a href="#count-of-cves-at-or-above-cvss-base-score-and-cvss-base-and-threat-score" class="md-nav__link">
684+
<span class="md-ellipsis">
685+
Count of CVEs at or above CVSS Base Score and CVSS Base and Threat Score
686+
</span>
687+
</a>
688+
689689
</li>
690690

691691
<li class="md-nav__item">
@@ -1350,15 +1350,6 @@
13501350
</span>
13511351
</a>
13521352

1353-
</li>
1354-
1355-
<li class="md-nav__item">
1356-
<a href="#count-of-cves-at-or-above-cvss-base-score" class="md-nav__link">
1357-
<span class="md-ellipsis">
1358-
Count of CVEs at or above CVSS Base Score
1359-
</span>
1360-
</a>
1361-
13621353
</li>
13631354

13641355
<li class="md-nav__item">
@@ -1378,6 +1369,15 @@
13781369
</span>
13791370
</a>
13801371

1372+
</li>
1373+
1374+
<li class="md-nav__item">
1375+
<a href="#count-of-cves-at-or-above-cvss-base-score-and-cvss-base-and-threat-score" class="md-nav__link">
1376+
<span class="md-ellipsis">
1377+
Count of CVEs at or above CVSS Base Score and CVSS Base and Threat Score
1378+
</span>
1379+
</a>
1380+
13811381
</li>
13821382

13831383
<li class="md-nav__item">
@@ -1420,7 +1420,7 @@ <h1 id="common-vulnerability-scoring-system-cvss">Common Vulnerability Scoring S
14201420
<li><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Severity Rating</li>
14211421
<li><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Confidentiality, Integrity, Availability Impacts</li>
14221422
</ul>
1423-
<p><img alt="🧑‍💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /> <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/cisa_kev_epss_cvss.ipynb">Source Code</a> </p>
1423+
<p><img alt="🧑‍💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /> <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/cisa_kev_epss_cvss.ipynb">Source Code</a> and <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/cvss-bt.ipynb"><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base vs <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base &amp; Threat Source Code</a></p>
14241424
</div>
14251425
<h2 id="cvss-severity-rating-scale"><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Severity Rating Scale<a class="headerlink" href="#cvss-severity-rating-scale" title="Permanent link">&para;</a></h2>
14261426
<div class="admonition quote">
@@ -1456,8 +1456,9 @@ <h2 id="cvss-severity-rating-scale"><abbr title="Common Vulnerability Scoring Sy
14561456
</div>
14571457
<div class="admonition tip">
14581458
<p class="admonition-title">Don't use <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Scores alone to assess risk.</p>
1459-
<p>Many organizations use <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Scores alone to assess risk despite repeated guidance against this.<br />
1460-
<strong>A Critical or High <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Severity is not the same as a Critical or High <abbr title="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr>. There's a &gt;10x difference in counts of CVEs</strong> for these 2 groups:</p>
1459+
<p>Many organizations use <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Scores alone to assess risk despite repeated guidance against this. </p>
1460+
<p><strong>A Critical or High <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Severity is not the same as a Critical or High <abbr title="The likelihood of a vulnerability being exploited and the potential impact of such an exploit on an organization.">Risk</abbr>.</strong></p>
1461+
<p><strong>There's a ~10x difference in counts of CVEs</strong> for these 2 groups:</p>
14611462
<ul>
14621463
<li><strong>&gt;50% of CVEs are ranked Critical or High <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> rating (<abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> score 7+)</strong></li>
14631464
<li><strong>~~5% of CVEs are exploited in the wild</strong></li>
@@ -1529,14 +1530,6 @@ <h2 id="cvss-confidentiality-integrity-availability-impacts"><abbr title="Common
15291530
</li>
15301531
</ol>
15311532
</div>
1532-
<h2 id="count-of-cves-at-or-above-cvss-base-score">Count of CVEs at or above <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Score<a class="headerlink" href="#count-of-cves-at-or-above-cvss-base-score" title="Permanent link">&para;</a></h2>
1533-
<figure>
1534-
<p><img alt="Image title" src="../../assets/images/cvss_hist.png" />
1535-
</p>
1536-
<figcaption> How many CVEs are at/above a given CVSS score? <br>
1537-
The continuous line is a polynomial regression of order 2.
1538-
</figcaption>
1539-
</figure>
15401533
<h2 id="cvss-exploit-maturity"><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Exploit Maturity<a class="headerlink" href="#cvss-exploit-maturity" title="Permanent link">&para;</a></h2>
15411534
<p>In addition to the <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Metrics which are commonly used, <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> supports other Metrics, including Threat Metrics.</p>
15421535
<div class="admonition quote">
@@ -1554,6 +1547,36 @@ <h3 id="cvss-v31"><abbr title="Common Vulnerability Scoring System Standard. A f
15541547
<li><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U">Unproven (U): 9.0</a> </li>
15551548
<li><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H">Not Defined (X): 9.8</a> results in the same score as <a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H">High (H): 9.8</a></li>
15561549
</ul>
1550+
<div class="admonition tip">
1551+
<p class="admonition-title">An example project that enriches <abbr title="National Vulnerability Database">NVD</abbr> <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores to include Temporal &amp; Threat Metrics</p>
1552+
<p>"<a href="https://github.com/t0sche/cvss-bt">Enriching the <abbr title="National Vulnerability Database">NVD</abbr> <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores to include Temporal &amp; Threat Metrics</a>" is an example project
1553+
where the <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Exploit Code Maturity/Exploitability (E) Temporal Metric
1554+
is continuously updated.</p>
1555+
<ul>
1556+
<li>Fetches <abbr title="Exploit Prediction Scoring System">EPSS</abbr> scores every morning</li>
1557+
<li>Fetches <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores from <abbr title="National Vulnerability Database">NVD</abbr> if there are new <abbr title="Exploit Prediction Scoring System">EPSS</abbr> scores.</li>
1558+
<li>Calculates the Exploit Code Maturity/Exploitability (E) Metric when
1559+
new data is found.</li>
1560+
<li>Provides a resulting <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr>-BT score for each <abbr title="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr></li>
1561+
</ul>
1562+
<p>It uses an <abbr title="Exploit Prediction Scoring System">EPSS</abbr> threshold of 36% as the threshold for High for Exploit Code Maturity/Exploitability (E).</p>
1563+
</div>
1564+
<h3 id="count-of-cves-at-or-above-cvss-base-score-and-cvss-base-and-threat-score">Count of CVEs at or above <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Score and <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base and Threat Score<a class="headerlink" href="#count-of-cves-at-or-above-cvss-base-score-and-cvss-base-and-threat-score" title="Permanent link">&para;</a></h3>
1565+
<p>The data from "<a href="https://github.com/t0sche/cvss-bt">Enriching the <abbr title="National Vulnerability Database">NVD</abbr> <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores to include Temporal &amp; Threat Metrics</a>" is used.</p>
1566+
<p><img alt="🧑‍💻" class="twemoji" src="https://cdn.jsdelivr.net/gh/jdecked/twemoji@15.0.3/assets/svg/1f9d1-200d-1f4bb.svg" title=":technologist:" /> <a href="https://github.com/RiskBasedPrioritization/RiskBasedPrioritizationAnalysis/blob/main/analysis/cvss-bt.ipynb"><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base vs <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base &amp; Threat Source Code</a></p>
1567+
<figure>
1568+
<p><img alt="Image title" src="../../assets/images/cvss_b_bt.png" />
1569+
</p>
1570+
<figcaption> How many CVEs are at/above a given CVSS score? <br>
1571+
The continuous line is a polynomial regression of order 2.
1572+
</figcaption>
1573+
</figure>
1574+
<div class="admonition observations">
1575+
<p class="admonition-title">Observations</p>
1576+
<ol>
1577+
<li>There is a significant difference in the count of CVEs above <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Score ~9 for <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base, and <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base and Threat. In other words, for <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base and Threat there's a lot less CVEs above a score of ~9.</li>
1578+
</ol>
1579+
</div>
15571580
<h3 id="cvss-v40"><abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> v4.0<a class="headerlink" href="#cvss-v40" title="Permanent link">&para;</a></h3>
15581581
<p>The Threat Metrics - Exploit Maturity (E) value causes the <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> v4.0 Score to vary slightly</p>
15591582
<ul>
@@ -1570,20 +1593,6 @@ <h3 id="cvss-v40"><abbr title="Common Vulnerability Scoring System Standard. A f
15701593
<p>There's a big difference in likelihood of exploitation, and associated populations of CVEs, in Attacked vs POC.</p>
15711594
<p>However, the <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Score changes only slightly between these - and that slight variation in score does not significantly change the counts of CVEs above the score per <a href="#count-of-cves-at-or-above-cvss-base-score">Count of CVEs at or above <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Base Score</a>.</p>
15721595
<p><strong>The convenience of a single <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> score comes with the cost of not being able to understand or differentiate between the risk factors from the score, and not being able to prioritize effectively using the score.</strong></p>
1573-
<div class="admonition tip">
1574-
<p class="admonition-title">An example project that enriches <abbr title="National Vulnerability Database">NVD</abbr> <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores to include Temporal &amp; Threat Metrics</p>
1575-
<p>"<a href="https://github.com/t0sche/cvss-bt">Enriching the <abbr title="National Vulnerability Database">NVD</abbr> <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores to include Temporal &amp; Threat Metrics</a>" is an example project
1576-
where the <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> Exploit Code Maturity/Exploitability (E) Temporal Metric
1577-
is continuously updated.</p>
1578-
<ul>
1579-
<li>Fetches <abbr title="Exploit Prediction Scoring System">EPSS</abbr> scores every morning</li>
1580-
<li>Fetches <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr> scores from <abbr title="National Vulnerability Database">NVD</abbr> if there are new <abbr title="Exploit Prediction Scoring System">EPSS</abbr> scores.</li>
1581-
<li>Calculates the Exploit Code Maturity/Exploitability (E) Metric when
1582-
new data is found.</li>
1583-
<li>Provides a resulting <abbr title="Common Vulnerability Scoring System Standard. A framework for scoring the severity of vulnerabilities based on factors such as exploitability and impact.">CVSS</abbr>-BT score for each <abbr title="CVE Common Vulnerability and Exposures. A standardized list of publicly known vulnerabilities and exposures maintained by the MITRE Corporation.">CVE</abbr></li>
1584-
</ul>
1585-
<p>It uses an <abbr title="Exploit Prediction Scoring System">EPSS</abbr> threshold of 36% as the threshold for High for Exploit Code Maturity/Exploitability (E).</p>
1586-
</div>
15871596
<div class="admonition success">
15881597
<p class="admonition-title">Takeaways</p>
15891598
<ol>

0 commit comments

Comments
 (0)