The CVE Wayback Machine: Measuring Coordinated Disclosure from Exploits against Two Years of Zero-Days

Eric Pauley, Paul Barford, Patrick McDaniel

Research output: Chapter in Book/Report/Conference proceedingConference contribution

1 Scopus citations

Abstract

Software security depends on coordinated vulnerability disclosure (CVD) from researchers, a process that the community has continually sought to measure and improve. Yet, CVD practices are only as effective as the data that informs them. In this paper, we use DScope, a cloud-based interactive Internet telescope, to build statistical models of vulnerability lifecycles, bridging the data gap in over 20 years of CVD research. By analyzing application-layer Internet scanning traffic over two years, we identify real-world exploitation timelines for 63 threats. We bring this data together with six additional datasets to build a complete birth-to-death model of these vulnerabilities, the most complete analysis of vulnerability lifecycles to date. Our analysis reaches three key recommendations: (1) CVD across diverse vendors shows lower effectiveness than previously thought, (2) intrusion detection systems are underutilized to provide protection for critical vulnerabilities, and (3) existing data sources of CVD can be augmented by novel approaches to Internet measurement. In this way, our vantage point offers new opportunities to improve the CVD process, achieving a safer software ecosystem in practice.

Original languageEnglish (US)
Title of host publicationIMC 2023 - Proceedings of the 2023 ACM on Internet Measurement Conference
PublisherAssociation for Computing Machinery
Pages236-252
Number of pages17
ISBN (Electronic)9798400703829
DOIs
StatePublished - Oct 24 2023
Event23rd ACM Internet Measurement Conference, IMC 2023 - Montreal, Canada
Duration: Oct 24 2023Oct 26 2023

Publication series

NameProceedings of the ACM SIGCOMM Internet Measurement Conference, IMC
ISSN (Print)2150-3761

Conference

Conference23rd ACM Internet Measurement Conference, IMC 2023
Country/TerritoryCanada
CityMontreal
Period10/24/2310/26/23

All Science Journal Classification (ASJC) codes

  • Software
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'The CVE Wayback Machine: Measuring Coordinated Disclosure from Exploits against Two Years of Zero-Days'. Together they form a unique fingerprint.

Cite this