Forecasting Zero-Day Vulnerabilities

David C. Last · 2016

It seems that computer network defenders are always two steps behind attackers. This is due in part to the need for defenders to protect against the exploitation of zero-day vulnerabilities which they may not yet know exist. If network defenders were able to forecast the location and severity of zero-day vulnerabilities that would be discovered in the near future, this would be a valuable tool. This paper describes ongoing research that seeks to develop Vulnerability Discovery Models that will provide forecasts for zero-day vulnerability discovery rates. The initial work addresses forecasts at the global and category (web browser, operating system, and video player) levels, and this will be extended to individual software applications in the future. This research has developed three distinct zero-day vulnerability forecast suites, one based on regression and two based on machine learning. The accuracy of several of the forecast models from each forecast suite is evaluated, and the results are promising for the future development of these forecast models. Future work in this area will involve combining individual forecast models into a consensus forecast model, as well as extending the forecast models to the software application level.

Read the paper · More papers on PaperTik