Paul's Security Weekly (Video)

How do we patch the right things? - PSW #840


Listen Later

Every week here on the show we talk about vulnerabilities and exploits. Typically we recommend that organizations remediate these vulnerabilities in some way. But how? And more importantly, which ones? Some tools we have to help us are actually not all that helpful at time, such as:

  • Mitre Att&ck - Don't get me wrong, this is a great project and Adam and team is doing a great job. However, its not a complete picture as we can't possibly know about every attack vector (or can we?). People seem to think if they cover everything in the framework they will be secure. You can't cover everything in the framework because each technique can be utilized by an attack in a hundred different ways.
  • CVSS - Anyone can apply a score, but who is correct? Good that we have a way to score things, but then people will just use this as a basis for what they patch and what they do not. Also, chaining vulnerabilities is a thing, but we seem to lack any way to assign a score to multiple vulnerabilities at once (different from a technique). Also, some things don't get a CVE, how are you tracking, assessing risk, and patching these?
  • CISA KEV - Again, love the project and Tod is doing amazing work. However, what about things that do not get a CVE? Also, how do you track every incident of an attacker doing something in the wild? Also, there is frequency, just because something got exploited once, does that mean you need to patch it right away? How are we tracking how often something is exploited as it is not just a binary "yes, its exploited" or "no, it is not".
  • EPSS - I do like the concept and Wade and Jay are doing amazing work. However, there seems to be a "gut reaction" thing going on where we do see things being exploited, but the EPSS score is low. How can we get better at predicting? We certainly have enough data, but are we collecting the right data to support a model that can tell us what the attackers will do next?

Show Notes: https://securityweekly.com/psw-840

...more
View all episodesView all episodes
Download on the App Store

Paul's Security Weekly (Video)By Security Weekly Productions

  • 5
  • 5
  • 5
  • 5
  • 5

5

2 ratings


More shows like Paul's Security Weekly (Video)

View all
Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

MacBreak Weekly (Video) by TWiT

MacBreak Weekly (Video)

355 Listeners

Security Now (Video) by TWiT

Security Now (Video)

148 Listeners

RunAs Radio by Richard Campbell

RunAs Radio

83 Listeners

Windows Weekly (Video) by TWiT

Windows Weekly (Video)

79 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

654 Listeners

Security Weekly News (Video) by Security Weekly Productions

Security Weekly News (Video)

5 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,044 Listeners

First Ring Daily by Paul Thurrott and Brad Sams

First Ring Daily

51 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

92 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

138 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

169 Listeners