Task-specific dataset for Bridging the Gap Between Security Metrics and Key Risk Indicators: A Data-Driven Approach to Vulnerability Prioritization
收藏资源简介:
This work investigates the effectiveness of Key Risk Indicators (KRIs) compared to traditional Security Metrics (SMs) in cyber risk management and vulnerability prioritization. While SMs such as the Common Vulnerability Scoring System (CVSS) severity scores remain widely adopted by organizations, empirical evidence demonstrates their failure to capture real-world exploitation likelihood, resulting in suboptimal resource allocation in vulnerability remediation. To address this critical gap, we propose a multidimensional approach that integrates the Exploit Prediction Scoring System (EPSS), CVSS severity ratings, and Common Weakness Enumeration (CWE) prevalence data into a composite KRI framework. Using publicly available datasets, including the Known Exploited Vulnerabilities (KEVs) catalog, EPSS scores, and Common Vulnerabilities and Exposures (CVEs) data with associated CWE identifiers, we developed a reproducible pipeline for data integration, feature engineering, and predictive modeling. Logistic Regression classifiers were trained to predict exploitation likelihood, with evaluation conducted using Receiver Operating Characteristic Area Under the Curve (ROC-AUC) and Area Under the Precision-Recall Curve (AUPRC) metrics. Our results indicate that KRIs significantly outperform traditional SMs, achieving a ROC-AUC score of 0.927 and AUPRC value of 0.223, compared to 0.747 and 0.011. These findings underscore the importance of risk-based vulnerability management practices and highlight the practical benefits of incorporating exploitability indicators and systemic weakness patterns into organizational prioritization strategies.



