Главная
Study mode:
on
1
Introduction
2
Vulnerabilities
3
What is CVSS
4
Double Vision
5
Insecurity
6
Data Sets
7
Distribution
8
Exploitability
9
Case Control Study
10
Comparison
11
Example
12
Sensitivity
13
Sensitivity vs Specificity
14
Pacing
15
Visualizing CVSS
16
Patching Policy
17
National Grid
18
Batches
19
Shock Analysis
20
CVSS Score
21
Temporal Scores
22
Temporal Information
Description:
Explore a critical analysis of the Common Vulnerability Scoring System (CVSS) in this Black Hat USA 2013 conference talk. Delve into the effectiveness of CVSS as a risk metric and prioritization tool for vulnerability patching. Examine real attack data to assess the practical implications of using CVSS scores for security decision-making. Learn about the potential over-investment risks associated with CVSS-based patching strategies, which can reach up to 300% of an optimal approach. Gain insights into the statistical significance of the findings and their practical applications. Evaluate whether CVSS is truly an effective method for prioritizing vulnerability management in your organization. Cover topics such as vulnerability assessment, data set analysis, exploitability factors, case control studies, sensitivity and specificity comparisons, and the impact of CVSS scores on patching policies.

How CVSS is DOSsing Your Patching Policy - and Wasting Your Money

Black Hat
Add to list
0:00 / 0:00