1 / 2100%
Data set description:
The NVD is nearly 180,000 records of vulnerabilities published for
nearly 20 years. Over the years, the data definitions and fields have
changed multiple times for example scoring. The current scoring
system is up to version 3. Each record contains over 35 different data
points including both version 2 scoring and version 3 scoring and is
identified by a unique CVE number. This makes it easy to join
complimenting information such as EPSS scores for each vulnerability.
The CVSS Base Metrics has three sub-groupings, exploitability
metrics, impact metrics, and scope. However, most vulnerabilities only
include the base exploitability and impact assessments. When looking
up a CVSS score for a vulnerability in the NVD, the reported score is
almost always the CVSS base score.
The Exploit Prediction Scoring System (EPSS) is the second set used to
complement the CVE dictionary. The EPSS is an open-source
collaboration that uses machine learning to estimate the likelihood
that a vulnerability will be exploited in the wild. The EPSS model scores
vulnerabilities between 0 and 1. The higher the score, the greater the
probability that a vulnerability will be exploited. (The EPSS Model,
2022) Every vulnerability in the CVE dictionary is scored. The EPSS
score will be joined together with the CVE number in the CVE
dictionary.
Lastly, the list of Common Weakness Enumeration (CWE) dataset will
be used to match vulnerabilities to weaknesses. The CWE dataset
contains 926 software and hardware weaknesses. Software
weaknesses contain 40 higher level categorical weaknesses. Hardware
weaknesses similarly contain 12 higher level categorical weaknesses.
Some weaknesses are already combined with the vulnerabilities.
CWEs will be combined using the matched weaknesses as supervised
learning to predict the likelihood of a match.
Challenges: Available but not used is the Common Platform
Enumeration (CPE). Many people have already reported on CVEs by
platforms. However, there are many problems with using the
platforms for analytics. First, participation in the NVD is voluntary for
manufacturers. Microsoft is an active participant with a whole range of
products that are widely used around the world. Tracking
vulnerabilities by CPE skews the results towards active participants
and the most widely used products. This can be an area for further
exploration by other analysts.
Students also viewed