1 / 2100%
Below is my project scope. I look forward to your review.
Data Analytics Project/Project Scope
The purpose of this project is to use machine learning to map
cybersecurity weaknesses to newly discovered cybersecurity
vulnerabilities. The scope of the data analytics problem that I am
analyzing is using natural language processing to map cybersecurity
weaknesses to cybersecurity vulnerabilities using keyword matching,
scoring CVEs according to the CIA triad, assess the OWASP Top 25,
and the impacts to prevent cybersecurity vulnerabilities.
Background:
NISTIR 8246 documents the process a record is entered into the NVD.
The number of CVEs created year over year has outpaced the ability to
maintain the CVE program with NVD’s limited resources. The solution
is a public/private partnership between the NVD analysts and private
Certificate Naming Authorities (CNA). The goal for CNAs is to maintain
Provider status which allows them to submit new vulnerabilities
directly and have a lower level of auditing. There are many ways a CNA
and a NVD analyst can have a mismatch including improper
identification of associated weaknesses, or scoring the vulnerability
across a range of factors such as the CIA triad. (Byers, Waltermire, &
Turner, NISTIR 8246: Collaborative Vulnerability Metadata, 2020)
Project Importance:
The National Vulnerability Database (NVD) has traditionally been
responsible for providing the metadata to the Common Vulnerability
Enumeration (CVE). The metadata include the scoring the
vulnerabilities and associating weaknesses. New systems are needed
to provide the data in a timely manner. (Byers, Waltermire, & Turner,
Collaborative Vulnerability Metadata Acceptance Process (CVMAP),
2020)
Business Objectives:
The cybersecurity business environment is constantly evolving. The
attack surface vulnerable to attack is growing exponentially as more
devices are connected to the internet. Information technology
companies, both hardware and software providers, are in a game of
cat-and-mouse to stay ahead of constantly evolving threats. The good
news is that cybersecurity researchers are getting better at identifying
zero-day vulnerabilities before they can be exploited. Teams like
Project Zero at Google are identifying vulnerabilities at a faster rate
than ever before. (Stone, 2022)
The first business objective is to provide a model to ease the analysis
of new CVEs to the NVD. This will enable more CVEs to be analyzed
and processed into the NVD. The second business objective is to
validate the OWASP Top 25 based off the Common Vulnerability
Scoring System (CVSS). The previous top 25 list was generated by
manually mapping weaknesses to vulnerabilities. (Chaudry et al, 2021)
A ML model can improve upon the manual process. The last business
objective is to develop tools for cybersecurity analysts to better score
CVEs – a key area addressed as a need for improvement.
References
Adam Chaudry, S. C. (2022, 05 31).
2021 CWE Top 25 Most
Dangerous Software Weaknesses.
Retrieved from cwe.mitre.org:
https://cwe.mitre.org/top25/archive/2021/2021_cwe_top25.html
Byers, R., Waltermire, D., & Turner, C. (2020, December).
Collaborative Vulnerability Metadata Acceptance Process (CVMAP)
.
Retrieved from National Vulnerability Database:
https://nvd.nist.gov/vuln/cvmap
Byers, R., Waltermire, D., & Turner, C. (2020, December).
NISTIR
8246: Collaborative Vulnerability Metadata.
Retrieved from NIST
Pubs: https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8246.pdf
NVD, N. (2022, 05 31).
API Products.
Retrieved from National
Vulnerability Database: https://nvd.nist.gov/developers/products
Stone, M. (2022, April 19).
The More You Know, The More You Know
You Don’t Know.
Retrieved from googleprojectzero.blogspot.com:
https://googleprojectzero.blogspot.com/2022/04/the-more-you-
know-more-you-know-you.html
Students also viewed