In cybersecurity, CVEs (Common Vulnerabilities and Exposures) are publicly disclosed hardware or software vulnerabilities. These vulnerabilities are documented and listed in the NVD database maintained by the NIST. Knowledge of the CVEs impacting an information system provides a measure of its level of security. This article points out that these vulnerabilities should be described in greater detail to understand how they could be chained together in a complete attack scenario. This article presents the first proposal for the CAPG format, which is a method for representing a CVE vulnerability, a corresponding exploit, and associated attack positions.
翻译:在网络安全领域,通用漏洞披露(CVE)是公开披露的硬件或软件漏洞。这些漏洞被记录并收录于美国国家标准与技术研究院维护的国家漏洞数据库(NVD)中。掌握影响信息系统的CVE信息能够衡量其安全水平。本文指出,需要更详细地描述这些漏洞,以理解它们如何串联成完整的攻击场景。本文首次提出CAPG格式方案,这是一种用于表示CVE漏洞、相应漏洞利用及其关联攻击位置的方法。