The Common Vulnerabilities and Exposures (CVE) Program's mission is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. A cybersecurity practitioner who suspects a software, hardware, or service vulnerability, can initiate a CVE-ID Requesting process, as defined by MITRE. This process is cumbersome, as it is entirely textual and evolvable, making it prone to incomplete description and misinterpretations. To automate and streamline the process, we developed a model of this process using Object-Process Methodology (OPM ISO 19450:2024). The model features computational capabilities, enabling practitioners to feed a textual description of the potential vulnerability they wish to report for CVE-ID Requesting. In response, the system provides all matching CVE Numbering Authority (CNA) instances in a descending relevance order. A survey that evaluates the effectiveness of this model-based approach has shown that it formally explicates the CVE-ID Requesting process and automates it. This greatly alleviates the task of determining what CNA is best suitable for examining the potential CVE for which a number is sought. Beyond streamlining and automating the process, this work demonstrates the benefits of adopting an approach to cybersecurity that standardizes and formulates global cybersecurity processes and systems. The approach facilitates the way professionals navigate their way in the complex, evolving web of hardware and software vulnerabilities.
更多
查看译文
关键词
common vulnerabilities and exposures (CVE),conceptual modeling,cybersecurity,knowledge representation,OPM ISO 19450