<p>Managing and remediating security vulnerabilities within complex IT environments is a continuous process. This process can often leave organizations with overwhelmed security teams and unresolved critical threats. Inefficient vulnerability management, particularly in prioritizing vulnerabilities, often leads to data breaches, financial losses, operational disruptions, regulatory noncompliance, and reputational harm. Traditional prioritization approaches largely rely on static factors such as CVSS scores, overlooking asset criticality and time-dependent exploitation risks. This paper introduces <b>VulnScore</b>, a deployed vulnerability prioritization system that derives a severity score—VulnScore Severity Rate—by integrating multiple crucial factors: Exploit Prediction Scoring System (EPSS), Vulners AI risk ratings, CVSS scores, and user-defined measures of system criticality. VulnScore is further embedded within <b>Reconmap</b>, an open-source penetration testing management platform, making it readily accessible to practitioners. Evaluation with 25 cybersecurity professionals was conducted through surveys and hands-on user testing. The major findings indicate that 92–96% of participants highlighted the ease of customization, integration, and responsiveness, while 88% agreed that VulnScore Severity Rate accurately reflected vulnerability severity. Performance testing showed near-real-time response (<InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(\approx 0.0002\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mo>≈</mo> <mn>0.0002</mn> </mrow> </math></EquationSource> </InlineEquation>s). The study concludes that VulnScore not only provides practical, real-time vulnerability management but also demonstrates clear improvements over existing prioritization systems that rely solely on static metrics such as the CVSS scores.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

VulnScore: A deployed system for patch prioritization combining human input and temporal threat intelligence

  • Norah Alqahtani,
  • Mohammed Almukaynizi

摘要

Managing and remediating security vulnerabilities within complex IT environments is a continuous process. This process can often leave organizations with overwhelmed security teams and unresolved critical threats. Inefficient vulnerability management, particularly in prioritizing vulnerabilities, often leads to data breaches, financial losses, operational disruptions, regulatory noncompliance, and reputational harm. Traditional prioritization approaches largely rely on static factors such as CVSS scores, overlooking asset criticality and time-dependent exploitation risks. This paper introduces VulnScore, a deployed vulnerability prioritization system that derives a severity score—VulnScore Severity Rate—by integrating multiple crucial factors: Exploit Prediction Scoring System (EPSS), Vulners AI risk ratings, CVSS scores, and user-defined measures of system criticality. VulnScore is further embedded within Reconmap, an open-source penetration testing management platform, making it readily accessible to practitioners. Evaluation with 25 cybersecurity professionals was conducted through surveys and hands-on user testing. The major findings indicate that 92–96% of participants highlighted the ease of customization, integration, and responsiveness, while 88% agreed that VulnScore Severity Rate accurately reflected vulnerability severity. Performance testing showed near-real-time response ( \(\approx 0.0002\) 0.0002 s). The study concludes that VulnScore not only provides practical, real-time vulnerability management but also demonstrates clear improvements over existing prioritization systems that rely solely on static metrics such as the CVSS scores.