Distributed Analysis Tool for Vulnerability Prioritization in Corporate Networks

Michał Walkowski, Maciej Krakowiak, Jacek Oko, S. Sujecki · 2020

One of the most underestimated factors in providing cybersecurity for corporational networks is the time factor corresponding to vulnerability and patch management. The time gap between public announcement of vulnerability and its detection, and reporting to interested stakeholders is the key to successful prevention of vulnerability exploitation by adversaries. Sometimes the time that passes since vulnerability scan is performed and time the report is received can extend to a month. Such delay may be a cause of significant risk or even damage done to the network by adversaries. To date organisations rely on log correlation in terms of introducing defenses. However, the accelerative vulnerability management, many different risks can be avoided completely. This work introduces a flexible system that collects information about all known vulnerabilities, gathers data from organizational inventory database, integrates with vulnerability scanners to retrieve scan results. Adopted approach results can be presented almost in real time to all interested stakeholders and thus help them react or plan actions promptly without unnecessary delay thus improving the Quatlity of Service.

Read the paper · More papers on PaperTik