Code Monkey home page Code Monkey logo

prioritizedriskremediation's Introduction

Risk-Based Prioritization of CVEs

A Risk-Based Prioritization Taxonomy for prioritizing CVEs (Common Vulnerabilities and Exposures).

Background

A Risk Remediation Taxonomy is defined here to support Risk Based Prioritization of CVEs:

  • the constituent components of risk and remediation for a CVE
  • the associated data sources for these components

A Risk-based Decision Tree is defined with

  • inputs for the Decision Tree Decision Nodes
  • output Decisions

The Risk Remediation Taxonomy and Decision Tree are part of a conference presentation by Yahoo Chris Madden: https://www.bsidesdub.ie/ May 27 2023.

Risk Remediation

A tree with the constituent components of Risk and Remediation for a CVE - Top Level

RiskRemediationTop

Diagram Source: RiskRemediation_top.puml

A tree with the constituent components of Risk and Remediation for a CVE - and associated data sources

RiskRemediation

Diagram Source: RiskRemediation.puml

Risk-based Decision Tree Decision Node Inputs

The inputs for the Decision Tree Decision Nodes - and associated data sources from Risk Remediation Taxonomy.

RiskRemediationTop

Diagram Source: DT_decisions.puml

Risk-based Decision Tree Decisions

The Decision Tree with output Decisions

RiskRemediationTop

Diagram Source: DT_Full.puml.

Contribute

Please refer to the Contributing.md file for information about how to get involved. We welcome issues, questions, and pull requests.

Plantuml

The diagram(s) are written in the wonderful Plantuml.

License

This project is licensed under the terms of the Apache 2.0 open source license. Please refer to LICENSE for the full terms.

prioritizedriskremediation's People

Contributors

crashedmind avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.