论文标题
脆弱性优先级:进攻性安全方法
Vulnerability Prioritization: An Offensive Security Approach
论文作者
论文摘要
组织在云环境中努力处理纯粹的漏洞。用于优先考虑漏洞的事实方法是使用常见的漏洞评分系统(CVSS)。但是,CVSS具有固有的局限性,使其成为优先级的理想选择。在这项工作中,我们提出了一种优先考虑漏洞的新方法。我们的方法灵感来自进攻安全从业人员如何执行渗透测试。我们通过为大型客户进行现实世界案例研究评估我们的方法,以及机器学习端到头的准确性。
Organizations struggle to handle sheer number of vulnerabilities in their cloud environments. The de facto methodology used for prioritizing vulnerabilities is to use Common Vulnerability Scoring System (CVSS). However, CVSS has inherent limitations that makes it not ideal for prioritization. In this work, we propose a new way of prioritizing vulnerabilities. Our approach is inspired by how offensive security practitioners perform penetration testing. We evaluate our approach with a real world case study for a large client, and the accuracy of machine learning to automate the process end to end.