meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, June 13th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 13 June 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Exploit Prediction; PACMAN Attack; Carrier Access Panels; Malicious PyPi;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, June 13th, 2020 edition of the Sandsenet Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich.

0:09.9

And today I'm according from Jacksonville, Florida.

0:13.9

Got an interesting diary by Russ from Friday, and it's about trying to predict how likely a vulnerability is being exploited.

0:24.3

First came up with a model. They call it the EPSS model or the exploit prediction scoring system

0:32.3

and made an API available. It allows you to look up the EPSS score for various vulnerabilities

0:40.3

based on their CVE. Now we do have the CVSS score. That score does indicate how severe a vulnerability is,

0:50.3

but of course does not necessarily predict if a vulnerability will actually be

0:55.2

exploited. And a real severe vulnerability you may care less about if it's not going to get

1:01.6

exploited. And that's always sort of a hard thing to sort of figure out. Well, first here came up

1:07.6

with a model that they consider somewhat valid in order to predict how likely

1:13.0

a vulnerability will be exploited in the next 30 days. Now to make it easier to interact with

1:20.3

the API that first offers Russ now created a little utility EPSS call that will allow you to interact with that API

1:31.9

and then retrieve the score based on dates.

1:37.4

So you also can change how it changes over date.

1:41.1

The two numbers that are typically being provided here by first, our first the EPSS

1:45.8

score itself, and then also a percentile, meaning how many vulnerabilities, are the percentage

1:51.5

of vulnerabilities that have a score of whatever the score of the vulnerabilities and lower.

1:57.4

So it's easy to see what sort of your top ranking vulnerabilities are based on their

2:04.5

likelihood of being actually exploited. Certainly an interesting and important project,

2:10.7

so take a look and let me know, let us know, sort of how these tools work, how these EPSS scores

2:17.2

work out for you.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.