Open ICS Advisory Dataset (OICSAD) v0.1.0: CISA ICS Advisories Joined to the Known Exploited Vulnerabilities Catalog
收藏资源简介:
An open, reproducible dataset of every industrial control system (ICS) and medical-device advisory that CISA has published in machine-readable CSAF 2.0 format, from 2010-02-27 to 2026-09-24, joined to CISA's Known Exploited Vulnerabilities (KEV) catalog. WHAT IS INCLUDED- advisories.csv: 3,937 advisories (3,749 ICSA, 188 ICSMA), one row per advisory, with normalized vendor, critical-infrastructure sector, CVSS summary, KEV counts and republication flags.- advisory_cves.csv: 14,487 advisory-CVE links with CWE, CVSS version/score/severity/attack vector, remediation categories and KEV fields.- cves.csv: 12,346 unique CVEs with first appearance, best CVSS score, KEV listing date, ransomware flag, a first-party/third-party component label for KEV-listed CVEs, and days from first ICS advisory to KEV listing.- vendor_map.csv: every raw vendor string (883) mapped to its normalized name (848), with the rule applied.- Pipeline code (Python, five numbered scripts), QA report, provenance log, codebook, limitations, figures, and the materials for the BSides talk "Building an Open ICS Vulnerability Dataset from Federal Sources". SOURCES (both fetched with git and pinned to commits)- CISA CSAF advisories, csaf_files/OT/white, github.com/cisagov/CSAF, commit 369141e (2026-09-24). U.S. government work, public domain.- CISA Known Exploited Vulnerabilities catalog, github.com/cisagov/kev-data (official mirror of cisa.gov/kev), catalog version 2026.09.25, commit 9dfdff6. CC0 1.0. HEADLINE FINDINGS- Advisory volume grew 3.6x, from 137 in 2015 to 489 in 2025. Siemens appears in 26.5% of advisories.- 60.8% of scored CVEs are High or Critical; 60.0% are network attack vector and 32.7% local.- Only 117 of 12,346 CVEs (0.9%) are in KEV. 100 of those 117 (85.5%) are third-party IT components embedded in OT products (e.g. Cisco IOS, Microsoft Windows, Chromium, Linux kernel, PAN-OS, FortiOS).- Of 76 KEV-listed CVEs first advised after KEV launched (2021-11-03), 51 were already in KEV when the ICS advisory was published (median gap -28 days). REPRODUCIBILITYRunning the five scripts with the pinned commits reproduces the processed tables byte-for-byte. Every number in the documents is generated from paper/stats.json. All QA hard checks pass (see data/processed/qa_report.txt). LIMITATIONSCoverage is CISA's CSAF corpus only; KEV is a floor for exploitation, not a complete record; the third-party label is a name-matching heuristic; republished vendor advisories keep the vendor's original dates; NVD and EPSS are not yet joined (planned for v0.2). See docs/LIMITATIONS.md before citing. Code is MIT-licensed; data and documents are CC BY 4.0. Use of this data does not imply endorsement by CISA or DHS. Code and first drafts of documentation were produced with AI assistance (Claude); the authors made the analytic decisions and verified the outputs.



