A Relevance Model for Threat-Centric Ranking of Cybersecurity Vulnerabilities
Published in Cybersecurity & Information Systems Information Analysis Center Journal, 2024
This paper presents a framework for vulnerability management that uses public data sources and adversary criteria from MITRE ATT&CK to prioritize vulnerabilities, demonstrating significant improvements over CVSS in identifying targeted vulnerabilities and reducing patching costs.
Recommended citation: McCoy, Corren; Gore, Ross J; Nelson, Michael L; Weigel, Michele. (2024). "A Relevance Model for Threat-Centric Ranking of Cybersecurity Vulnerabilities." Cybersecurity & Information Systems Information Analysis Center Journal. Special AI/ML Edition.
Download Paper