00:00

Understanding CVSS and EPSS in Cybersecurity

The Common Vulnerability Scoring System (CVSS) and the Exploit Prediction Scoring System (EPSS) are crucial metrics in cybersecurity for quantifying and prioritizing vulnerabilities based on severity and likelihood of exploitation. CVSS assigns numerical scores from 0 to 10, considering factors like exploitability and impact, while EPSS offers probabilistic predictions on real-world exploitation. Integrating EPSS with CVSS enhances threat intelligence and vulnerability management strategies for more effective response and mitigation.

alcauza
Download Presentation

Understanding CVSS and EPSS in Cybersecurity

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. …more than software, your IT partner 17/05/2024 Sicurezza ICT MILANO 28 Febbraio 2024

  2. Are we really sure that a vulnerability with a CVSS 10 rating will cause the end of the world? 2

  3. CVSS EPSS 3

  4. What is CVSS? The Common Vulnerability Scoring System Common Vulnerability Scoring System is a standard metric in cybersecurity that quantifies the severity of vulnerabilities with a numerical score. CVSS helps prioritize responses to security threats efficiently. Standard Metrics-based Consistent It considers various factors such as exploitability, impact, and complexity to assign a numerical score to vulnerabilities. It allows organizations to compare and prioritize vulnerabilities to meet needs and risk management strategies IT provides a standardized method for assessing and scoring the severity of vulnerabilities from 0 to 10 across different systems and organizations published by 4

  5. …and what about EPSS? The Exploit Prediction Scoring System Exploit Prediction Scoring System offers a probabilistic approach to vulnerability management. . It is a data-driven model that estimates the likelihood of a software vulnerability being actively exploited in the next 30 days. Data-driven Probabilistic Actionable It helps prioritize patching efforts by highlighting vulnerabilities with a higher chance of real-world exploitation It relies on historical data and daily exploitations activities to generate its predictions It assigns scores between 0 and 1, representing the likelihood of a vulnerability being exploited published by 5

  6. CVSS EPSS 6

  7. Example 1 Cisco EOL Software vulnerability CVE CVE--2021 2021--1459 1459 published in April 2021 CVSS EPSS Cisco affected products: • Firewall VPN Wireless-N RV110W • Router VPN RV130 • Router VPN Wireless-N RV130W • Router VPN Wireless-N RV215W 9.8 9.8 0.24 0.24% % SPOILER Software support Software support ended ended December December 2020 2020 It's not the end of the world! It's not the end of the world! https://www.cisco.com/c/en/us/products/collateral/routers/small-business-rv-series-routers/eos-eol-notice-c51-742771.pdf 7

  8. Example 2 A new Cisco vulnerability CVE CVE--2023 2023--20198 20198 OMG! published in October 2023 CVSS EPSS 10.0 10.0 91.92 91.92% % 8

  9. Example 2 A new Cisco vulnerability OMG! CVE CVE--2023 2023--20198 20198 published in October 2023 CVSS EPSS 10.0 10.0 91.92 91.92% % https://github.com/smokeintheshell/CVE-2023-20198 9

  10. What to do about the future?​ 10

  11. Use EPSS together with CVSS in your Threat Intelligence activities to give better insights on the detected vulnerability Opening ticket criteria:  CVSS > 9.0  CVSS > 7.0 and EPSS > 80% 11

  12. Integrate EPSS in your SOC to improve your vulnerability management monthly process Opening ticket criteria:  CVSS > 5.0  CVSS > 5.0 and EPSS > 60% 12

  13. Analyze EPSS in your vulnerability assessment activities 13

  14. Not sure where to start? 14

  15. Check FIRST’s list of vendors using EPSS https://www.first.org/epss/who_is_using/ 15

  16. info@wuerth-phoenix.com www.wuerth-phoenix.com

More Related