JULY - 2023ENTERPRISE SECURITY| | 9mitigating controls are in place (e.g., EDR, SIEM, NGAV, etc.)?Evaluate if the bug is known to be used by threat actors and/or malware. Open-source intelligence can be invaluable in this process of identifying vulnerabilities relevant to your threat model. For example, if you're worried about ransomware (and who isn't?) priority should be given to bugs leveraged by ransomware actors in real-world intrusions. If you suspect you are in the crosshairs of Fancy Bear, elevate remediation priority for the vulnerabilities targeted by this Russian adversary with a proclivity for espionage. Conversely, some vulnerabilities may be under active exploitation but remain outside of scope for your organization. Pay close attention if reporting suggests that an exploit is "highly targeted". It is not uncommon for vulnerabilities to be used in hyper-specific regional contexts, particularly by nation-state actors conducting surveillance. If a threat is not germane to your industry or geography, it should be deprioritized accordingly.Other signals that can help you predict exploitation include social media chatter and honeypots. If a bug is being discussed all over Twitter, it could be significant. Similarly, if honeypots are detecting scans or full-blown exploitation attempts for a particular vulnerability, this should raise the priority level for that bug.The exact algorithm you use will depend on what data sources you have available. There are many paths to success and many opportunities for refinement here. As long as the model you choose is predictive of exploit and logically defensible, you should be well on your way to a successful vulnerability management program.By homing in on the tiny subset of truly dangerous bugs, you can have the best of both worlds in vulnerability management. You get to be an excellent steward of vulnerability risk for the organization. At the same time, you also lift a tremendous burden from operational teams that are chartered with researching, downloading, regression testing, and applying the deluge of security mitigation.The optimal remediation strategy in the modern era looks drastically different than it did in 1998. The goal is not to fix everything. Rather, the goal is to instrument all of your vulnerability data so that you can identify everything that you truly need to fix. If applied properly, data science and machine learning can help you safely eliminate more than 90% of your remediation workload while simultaneously reducing your organization's exposure to vulnerability risk. We owe a great debt to Mann and Christey for the interoperability we now enjoy thanks to the CVE standard. Still, laser focus is necessary to successfully navigate the growing storm of CVEs and to discern between mission-critical vulnerabilities and mundane exposures. ESIT MAY SOUND NOBLE TO TRY TO REMEDIATE EACH AND EVERY DEFICIENCY, BUT THE REALITY IS ONLY A VERY SMALL PERCENTAGE OF ALL VULNERABILITIES WILL EVER BE ADOPTED BY THREAT ACTORS AND USED IN A REAL-WORLD CYBER-ATTACK
<
Page 8 |
Page 10 >