xpertsystems/cyb009-sample
收藏资源简介:
CYB009模拟了企业资产舰队中的端到端漏洞生命周期,采用8阶段状态机,并校准了CVSS、EPSS和CISA KEV建模。具体包括:8阶段漏洞生命周期(从发现到修复部署)、漏洞类别(基于NIST NVD校准的CVSS分布,如内存损坏、注入家族、身份验证绕过等)、资产关键性层级(从关键到终端,具有差异化的SLA目标和修复行为)、CVSS基础、时间和环境评分(CVSS v3.1)、EPSS v3建模(利用预测分数和衰减因子)、CISA KEV目录建模(基于确认利用的列出概率)、零日漏洞利用建模(基于Mandiant M-Trends 2023校准)、供应链妥协传播建模(基于ENISA/Sonatype校准)、负责任披露建模(72%披露率基线)、补偿控制和风险接受结果,以及互联网暴露资产建模(38%暴露基线)。
CYB009 simulates end-to-end vulnerability lifecycles as an 8-phase state machine across enterprise asset fleets with calibrated CVSS, EPSS, and CISA KEV modeling, covering: 8-phase vulnerability lifecycle (discovery → cvss_scoring → vendor_disclosure → patch_development → patch_release → exploitation_in_wild → organisational_triage → remediation_deployment), vulnerability classes (NIST NVD-calibrated CVSS distributions: memory_corruption, injection_family, authentication_bypass, deserialization, cryptographic_weakness, race_condition, supply_chain, web_application, configuration, information_disclosure), asset criticality tiers (tier_1_critical, tier_2_business, tier_3_supporting, tier_4_endpoint — with differentiated SLA targets and remediation behaviors), CVSS Base, Temporal, and Environmental scoring (CVSS v3.1), EPSS v3 modeling (exploit prediction scores with decay factors), CISA KEV catalog modeling (listing probability conditional on confirmed exploitation), zero-day exploitation modeling (Mandiant M-Trends 2023 calibrated), supply chain compromise propagation modeling (ENISA / Sonatype calibrated), responsible disclosure modeling (72% disclosure rate baseline), compensating controls and risk acceptance outcomes, and internet-exposed asset modeling (38% exposure baseline).



