arXiv · 2206.11182
Vulnerability Prioritization: An Offensive Security Approach
Abstract
Organizations struggle to handle sheer number of vulnerabilities in their cloud environments. The de facto methodology used for prioritizing vulnerabilities is to use Common Vulnerability Scoring System (CVSS). However, CVSS has inherent limitations that makes it not ideal for prioritization. In this work, we propose a new way of prioritizing vulnerabilities. Our approach is inspired by how offensive security practitioners perform penetration testing. We evaluate our approach with a real world case study for a large client, and the accuracy of machine learning to automate the process end to end.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Muhammed Fatih Bulut, Abdulhamid Adebayo, Daby Sow, Steve Ocepek. 2022-06-22. Vulnerability Prioritization: An Offensive Security Approach. https://arxiv.org/abs/2206.11182
Cite the original work for its findings. Save a collection to share your selection of sources.