Chapter 60. Effective Vulnerability Remediation Using EPSS
Reet Kaur
Every day, new software vulnerabilities are disclosed. However, due to a lack of resources and conflicting business requirements, it is impossible for organizations to patch all these vulnerabilities and perform effective vulnerability remediation within defined service-level agreements (SLAs). Most companies can only fix between 5% and 20% of known vulnerabilities per month.
We also know that only a small subset of these many vulnerabilities are ever seen to be exploited in the wild. With a multitude of vulnerabilities to address and limited resources, it’s essential to prioritize remediation efforts while allocating resources more efficiently and effectively.
To tackle this issue, the FIRST (Forum of Incident Response and Security Teams) organization developed the Exploit Prediction Scoring System (EPSS). It is a community-driven effort to combine descriptive Common Vulnerabilities and Exposures (CVE) information with evidence of actual exploitation in the wild. By collecting and analyzing this information to include in our vulnerability management platforms, we may improve vulnerability prioritization by estimating the likelihood that a vulnerability may get exploited. The EPSS model produces a probability score between 0 and 1. The higher the score, the greater the probability that a vulnerability will be ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access