The CVE Wayback Machine: Measuring Coordinated Disclosure from Exploits against Two Years of Zero-Days


연구 분야: Strategies



학회: IMC '23: Proceedings of the 2023 ACM on Internet Measurement Conference


초록

Software security depends on coordinated vulnerability disclosure (CVD) from researchers, a process that the community has continually sought to measure and improve. Yet, CVD practices are only as effective as the data that informs them. In this paper, we use DScope, a cloud-based interactive Internet telescope, to build statistical models of vulnerability lifecycles, bridging the data gap in over 20 years of CVD research. By analyzing application-layer Internet scanning traffic over two years, we identify real-world exploitation timelines for 63 threats. We bring this data together with six additional datasets to build a complete birth-to-death model of these vulnerabilities, the most complete analysis of vulnerability lifecycles to date. Our analysis reaches three key recommendations: (1) CVD across diverse vendors shows lower effectiveness than previously thought, (2) intrusion detection systems are underutilized to provide protection for critical vulnerabilities, and (3) existing data sources of CVD can be augmented by novel approaches to Internet measurement. In this way, our vantage point offers new opportunities to improve the CVD process, achieving a safer software ecosystem in practice.


Author Profile
Eric Pauley

University of Wisconsin-Madison Madison WI USA

United States
Author Profile
Paul Robert Barford

University of Wisconsin-Madison Madison WI USA

United States
Author Profile
Patrick Drew McDaniel

University of Wisconsin-Madison Madison WI USA

United States

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 United States
사이트 ACM
좋아요 수 0

연관 논문 목록 (231건)