Graph-Based CPE Matching for Identification of Vulnerable Asset Configurations
Daniel Tovarňák, Lukáš Sadlek, Pavel Čeleda · Integrated Network Management · 2021
In this manuscript, we propose a graph-based approach for identification of vulnerable asset configurations via Common Platform Enumeration matching. The approach consists of a graph model and insertion procedure that is able to represent and store information about CVE vulnerabilities and different configurations of CPE-classified asset components. These building blocks are accompanied with a search query in Gremlin graph traversal language that is able to find all vulnerable pairs of CVEs and asset configurations in a single traversal, as opposed to a conventional brute-force approach.