2024å¹´8æ20æ¥ã«éå¬ããããVulsç¥ã#10 | èå¼±æ§ç®¡çã®æåç·ããªã¹ã¯è©ä¾¡ããSSVCãVEXãAIã¾ã§ããã®ã»ãã·ã§ã³ããæ®æ¥ï¼ æ¥é±ã§OK?ãéæåå¾ã®èå¼±æ§å¯¾å¿å¤æã«ä½¿ããSSVCã®ã㢠ãã®è¦ç¹ãæ¸ãèµ·ããè¨äºã§ãã YouTubeã¢ã¼ã«ã¤ãã¯ãã¡ãã§ãã ä¼å ´ã¸ã®è³ªå å æ¥IPAã®ä¸æ ¸äººæè²æããã°ã©ã åæ¥ããã¸ã§ã¯ãããããèå¼±æ§å¯¾å¿ã«ããããªã¹ã¯è©ä¾¡ææ³ã®ã¾ã¨ããã¨ããè³æãå ¬éããã¾ããããã®è³æã¯æ¬æ¥ç´¹ä»ããSSVCãEPSS, KEVãªã©ãæ¥æ¬èªã§ãããããã説æããã¦ãããã¾ãããªã¢ã¼ã¸ã«ã¤ãã¦ããã¤ãã®æ¹æ³ãè¨è¼ããã¦ããã®ã§ä¸èªããããããã¾ããããã®ä¸ã§ãã®å³ã®éã60社ã¸ã®ä¼æ¥ã«ã¢ã³ã±ã¼ããåã£ã¦ãã¾ãã æå¤ã«ããã£ãã®ããCVSSã®ç°å¢è©ä¾¡åºæºã60社ä¸15社ã使ã£ã¦ããç¹ã§ããç§ã¯2016å¹´ã«Vulsãéçºãã¦ä»¥éèå¼±æ§ç®¡çããã¼ãã«æ´»å
CVE_Prioritizerã¨SploitScanã§èãããKEV Catalog/EPSS/CVSS/SSVC æ¦è¦EPSSãKEV Catalogãæç¨ã«ä½¿ãããã¸ã§ã¯ããæè¿åºã¦ãã¾ããã ãããã«ã¤ãã¦å 容ã確èªããã©ã®ããã«ä½¿ããããåæ§ãªSSVCã¨ã©ãéãããè¦ã¦ããã¾ãã CVE_Prioritizer https://github.com/TURROKS/CVE_Prioritizer SploitScan https://github.com/xaitax/SploitScan Exective Summary EPSS, KEVã®ãã¼ã¿ç¹æ§ãèããå¿ è¦ããã EPSSã¯æ©ä¼ã®ã¿ãKEVã¯æ©ä¼ã¨èå¼±æ§ã示ã å½è©²ããã¸ã§ã¯ãã¯ä½¿ãããããCVSSã®ã¿ã§å¤æãã¦ããçµç¹ã¯ãCVE_Prioritizerãã¾ãã¯ä½¿ã£ã¦ã¿ãã®ãè¯ããããããªã å½è©²ããã¸ã§ã¯ã㯠ã·ã¹ãã åº
ã¢ã¡ãªã«æ¿åºCISAã«ãããæ¢ç¥ã®æªç¨ãããèå¼±æ§ã«ã¿ãã°ãã®æ¥æ¬èªè¨³
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}