Vulnerability Forecasting: Theory and Practice

6Citations
Citations of this article
24Readers
Mendeley users who have this article in their library.
Get full text

Abstract

It is possible to forecast the volume of CVEs released within a time frame with a given prediction interval. For example, the number of CVEs published between now and a year from now can be forecast within 8% of the actual value. Different predictive algorithms perform well at different lookahead values other than 365 days, such as monthly, quarterly, and half year. It is also possible to estimate the proportions of that total volume belonging to specific vendors, software, CVSS scores, or vulnerability types. Some vendors and products can be predicted with accuracy, others with too much uncertainty to be practically useful. This article documents which vendors are amenable to being forecasted. Strategic patch management should become much easier with these tools, and further uncertainty reductions can be built from the methodologies in this article.

Cite

CITATION STYLE

APA

Leverett, É., Rhode, M., & Wedgbury, A. (2022). Vulnerability Forecasting: Theory and Practice. Digital Threats: Research and Practice, 3(4). https://doi.org/10.1145/3492328

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free