æ¦è¦SSVC 㧠Deployer Tree ã使ãéã«ãHUMAN IMPACT ã®è¨å®ã«æ¸æããã¨ãå¤ãã¨æãã¾ããSSVC ã®å®ç¾©ä¸ã§ããè¤éãªã®ã§è©³ç´°ãé¿ãããã¦ããããã«è¦ãã¾ãã ã¾ããå®éç¨ä¸ã§ããèå¼±æ§ã²ã¨ã¤ãã¤ãHUMAN IMPACT ãå®ç¾©ãããã¨ã¯é£ããï¼èå¼±æ§æ¯ã«å®ç¾©ããããã¨ã«ãªãï¼ãä½ããã®æ¨æºåãå¿ è¦ã¨ãªãã¾ãã æ¬è¨äºã§ã¯ãSSVC ã®å®ç¾©ä¸ã§ã® HUMAN IMPACT ã«ã¤ãã¦ç¢ºèªããå®éç¨ä¸ã®HUMAN IMPACTã®å®ç¾©ã§å©ç¨ã§ããããªãã¬ã¼ã ã¯ã¼ã¯ããç´¹ä»ãã¾ãã Exective summaryæ¬æ¥çã« HumanImpact ã¯ãSituated Safety Impact 㨠Mission Impact ããã¨ã«èããã®ãè¯ãã¨æããã¦ãã¾ãã ããããªããç¾æç¹ã® SSVC ã®èãæ¹ã§ã¯ãå®è£ ã®ç°¡ç´ åã®ãããMission Impact
2024å¹´8æ20æ¥ã«éå¬ããããVulsç¥ã#10 | èå¼±æ§ç®¡çã®æåç·ããªã¹ã¯è©ä¾¡ããSSVCãVEXãAIã¾ã§ããã®ã»ãã·ã§ã³ããæ®æ¥ï¼ æ¥é±ã§OK?ãéæåå¾ã®èå¼±æ§å¯¾å¿å¤æã«ä½¿ããSSVCã®ã㢠ãã®è¦ç¹ãæ¸ãèµ·ããè¨äºã§ãã YouTubeã¢ã¼ã«ã¤ãã¯ãã¡ãã§ãã ä¼å ´ã¸ã®è³ªå å æ¥IPAã®ä¸æ ¸äººæè²æããã°ã©ã åæ¥ããã¸ã§ã¯ãããããèå¼±æ§å¯¾å¿ã«ããããªã¹ã¯è©ä¾¡ææ³ã®ã¾ã¨ããã¨ããè³æãå ¬éããã¾ããããã®è³æã¯æ¬æ¥ç´¹ä»ããSSVCãEPSS, KEVãªã©ãæ¥æ¬èªã§ãããããã説æããã¦ãããã¾ãããªã¢ã¼ã¸ã«ã¤ãã¦ããã¤ãã®æ¹æ³ãè¨è¼ããã¦ããã®ã§ä¸èªããããããã¾ããããã®ä¸ã§ãã®å³ã®éã60社ã¸ã®ä¼æ¥ã«ã¢ã³ã±ã¼ããåã£ã¦ãã¾ãã æå¤ã«ããã£ãã®ããCVSSã®ç°å¢è©ä¾¡åºæºã60社ä¸15社ã使ã£ã¦ããç¹ã§ããç§ã¯2016å¹´ã«Vulsãéçºãã¦ä»¥éèå¼±æ§ç®¡çããã¼ãã«æ´»å
2024å¹´7æ8æ¥ã«éå¬ããããã¸ã§ã¼ã·ã¹ãã¼ã¼ã¯ èå¼±æ§ç¥ãï½èå¼±æ§ã®å ¨ä½åã¨ä»ãåãæ¹ï½ãã®ã»ãã·ã§ã³ãSSVC DeepDiveãã®å 容ã§ãã ãããã®é©ç¨é åºã¯ãCVSSã®é«ãèå¼±æ§ãããããã§ã¯å®éã®éç¨ã¯åãã¾ãããSSVCã¯ãæ»æè ç®ç·ãåãå ¥ããèå¼±æ§è©ä¾¡ãã¬ã¼ã ã¯ã¼ã¯ã§ãç±³å½æ¿åºã§ãæ¡ç¨ããã¦ãã¾ããæ¬ã»ãã·ã§ã³ã§ã¯ãSSVCãæ´»ç¨ãããã¨ã§ãã©ã®ããã«èå¼±æ§ç®¡çãæ¹åãããã®ããå¾¹åºè§£èª¬ãã¾ããCVSSã ãã§ã¯ä¸ååãªæ¹ã«å¿ è¦ã®å 容ã§ãã Xã§ã®ã¸ã§ã¼ã·ã¹ãªèª°ãã®ã¤ã¶ããï¼æç²ï¼ã©ã³ãµã ã¦ã§ã¢ã®ãã¥ã¼ã¹ã§é¨ããã¦ããä¸ãXï¼æ§Twitterï¼ã«ã¦ãããªçºè¨ãç®ã«ãã¾ãããä»ååå ããã¦ããã¸ã§ã¼ã·ã¹ã®çããããå æ ãªæ©ã¿ãæ±ãã¦ããã¨æããç´¹ä»ãã¾ãã Xã§ã®ã¸ã§ã¼ã·ã¹ãªèª°ãã®ã¤ã¶ããã¾ã¨ããã¨ããããªå 容ã«ãªãã¨æãã¾ãã ï¼ä¼å ´ã®æ ã·ã¹ã®æ¹ãé ·ãæ¹å¤æ°ï¼ å ¬éããã
CVE_Prioritizerã¨SploitScanã§èãããKEV Catalog/EPSS/CVSS/SSVC æ¦è¦EPSSãKEV Catalogãæç¨ã«ä½¿ãããã¸ã§ã¯ããæè¿åºã¦ãã¾ããã ãããã«ã¤ãã¦å 容ã確èªããã©ã®ããã«ä½¿ããããåæ§ãªSSVCã¨ã©ãéãããè¦ã¦ããã¾ãã CVE_Prioritizer https://github.com/TURROKS/CVE_Prioritizer SploitScan https://github.com/xaitax/SploitScan Exective Summary EPSS, KEVã®ãã¼ã¿ç¹æ§ãèããå¿ è¦ããã EPSSã¯æ©ä¼ã®ã¿ãKEVã¯æ©ä¼ã¨èå¼±æ§ã示ã å½è©²ããã¸ã§ã¯ãã¯ä½¿ãããããCVSSã®ã¿ã§å¤æãã¦ããçµç¹ã¯ãCVE_Prioritizerãã¾ãã¯ä½¿ã£ã¦ã¿ãã®ãè¯ããããããªã å½è©²ããã¸ã§ã¯ã㯠ã·ã¹ãã åº
ããã«ã¡ã¯ãäºä¸ã§ãã FutureVulsã¯ãæ¥ã æ´æ°ãããèå¼±æ§æ å ±ãè£è¶³ããããå¹æçãªéç¨ã»ç®¡çããµãã¼ãããããµã¼ãã¹ã§ããã 2022/9/13ãªãªã¼ã¹ã«ã¦éç¨é¨åã§æç¨ãªSSVC(Stakeholder-Specific Vulnerability Categorization)ããµãã¼ããã¾ããã æ¬ç¨¿ã§ã¯ãèå¼±æ§å¯¾å¿ã®ç¾ç¶ããSSVCã®èª¬æãSSVCã®é©ç¨ä¾ã説æãã¾ãã ç®æ¬¡ èå¼±æ§å¯¾å¿ã®ç¾ç¶ åé¡ç¹ ã©ããããããã®ã SSVCã¨ã¯ æ¦è¦ ã©ã®ãããªå©ç¹ãããã®ã SSVCãé©ç¨ãã å¾æ¥ã®å¤æ SSVCã§ã®å¤æ ã¾ã¨ã èå¼±æ§å¯¾å¿ã®ç¾ç¶èå¼±æ§ãæ¤ç¥ããå¾ã«ã©ã®ããã«å¤æ/対å¿ããã®ããã¯æ©ã¿ã©ããã®å¤ãåé¡ã§ãã ä¸è¬çã«ã¯ä»¥ä¸ãèæ ®ãã¦å¯¾å¿ãæ¤è¨ãã¦ãã¾ãã èå¼±æ§èªä½ã®å±éºåº¦ èªã·ã¹ãã ã¸ã®å½±é¿åº¦ 対çé£æ度 æªå¯¾çã§ã®ãªã¹ã¯ ãã®çºãä¸è¨ãå¤æããåºæºãçµç¹ã§
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}