4 ms·
I've seen a bit of discussion lately about EPSS[0], which is a model that tries to take more practical metrics about any given CVE (including pieces of the CVSS
by nyx 3y ago
I've seen a bit of discussion lately about EPSS[0], which is a model that tries to take more practical metrics about any given CVE (including pieces of the CVSS, but also things like whether there's a GitHub PoC or if it's up on ExploitDB) and return a real-world exploitability score out of 100.
I can't help but imagine something like this is where we're headed, given how counterproductive it can be to make decisions based on CVSS scores...
[0]: https://www.first.org/epss/model https://www.first.org/epss/model
- ploxiln 3y agoThe problem is that a measure became a target. Most companies with a significant internet presence and a "cybersecurity" division have a policy of patching all CVEs. They can't understand vulnerabilities, there are too many and it's too hard, so the policy is to buy products that scan for software versions with known CVEs, and require other teams to patch/upgrade them. This is how most of the industry works now. So of course there is now huge motivation to get these CVE things, inflate them, never under-grade them, just in case ... so of course CVEs are becoming more noisy and useless, and many orgs (including my company) are now moving to EPSS. Just give it a few years though, this EPSS will probably degrade just like CVE as it becomes widely embedded in enterprise security processes.
- namaria 3y agoYeah that chimes with my experience. "Cybersecurity" (a name I hate by the way) without threat modelling and analyzing trade-offs is just compliance. There is a lot of bike shedding, cargo cults and general bs "box checking" work. So many players selling "AI" and visuals in the form of overly complicated "scanning" and CVE database querying, which is little more than checking and matching versions, or circular metadata writing and reading. I got in and out of the field in about a year.
- asciii 3y ago+1 I worked in sec analytics and it was just a bunch of ppl sending me excels with cves and devices. Not to mention the team on the other side of the company that deems something critical so now we have multiple tools scanning, feeding garbage data and a bunch of operations folks patching…only to rinse and repeat.