遇见数据集

Task-specific dataset for Context-Aware Vulnerability Prioritisation: Integrating Key Control Indicators into a Composite Cyber Risk Framework

收藏
Zenodo2026-08-13 更新2026-08-20 收录
官方服务:

资源简介:

Traditional vulnerability prioritisation relies on the Common Vulnerability Scoring System (CVSS), yet empirical studies demonstrate that CVSS-only classifiers perform near-randomly for real-world exploitation prediction. Composite Key Risk Indicators (KRIs) that integrate exploit probability (EPSS), technical severity (CVSS), and systemic weakness prevalence (CWE) have been shown to improve prioritisation substantially. However, existing KRI frameworks treat all organisations identically, ignoring whether the controls defending each vulnerability's attack path are implemented. This paper addresses this gap by proposing the Context-Adjusted Key Risk Indicator (CA-KRI): a novel framework that extends KRIs by incorporating Key Control Indicators, as a contextual modifier of threat-based risk scores. Using publicly available vulnerability data comprising Common Vulnerabilities and Exposures (CVE) records enriched with EPSS scores, CVSS severity, CWE classifications, and validated against the CISA Known Exploited Vulnerabilities catalogue as ground truth, we evaluate CA-KRI against CVSS and threat-only KRI baselines across five metrics: ROC-AUC, AUPRC, Precision@k, Remediation Value Capture (RVC@k), and severity-stratified recall. Results demonstrate that CA-KRI achieves RVC@1000 = 0.3177 versus KRI = 0.3172, while maintaining ROC-AUC = 0.708, consistent with the theoretically expected behaviour of a prioritisation re-ranker rather than a new classifier.

提供机构:
Zenodo
创建时间:
2026-08-13
二维码
社区交流群
二维码
科研交流群
商业服务