CVE representation to build attack positions graphs (M. Poisson)

Описание к видео CVE representation to build attack positions graphs (M. Poisson)

In cybersecurity, CVEs (Common Vulnerabilities and Exposures) are publicly disclosed hardware or software vulnerabilities. These vulnerabilities are documented and listed in the NVD database maintained by the NIST. Knowledge of the CVEs impacting an information system provides a measure of its level of security. Our work points out that these vulnerabilities should be described in greater detail to understand how they could be chained together in a complete attack scenario.  We present the first proposal for the CAPG (CVE representation to build Attack Positions Graphs) format, which is a method for representing a CVE vulnerability, a corresponding exploit, and associated attack positions.

Комментарии

Информация по комментариям в разработке