GitHub 参与信号用于 CVE 优先级排序:GitHub 流行度指标(GPM)
GitHub Engagement Signals for CVE Prioritization: The GitHub Popularity Metric (GPM)
浏览论文内容
中文总结 AI 辅助
针对漏洞优先级排序的挑战,提出基于 GitHub 仓库流行度(星标、分叉、用户数)的 GPM 指标,与现有指标比较并集成到 EPSS v5,为防御者提供新见解。
中文摘要 AI 辅助
攻击者可以利用单个漏洞危害多个系统,而防御者需要修复其系统中的所有安全弱点。这种不对称性使防御者处于不利地位。安全漏洞以惊人的速度被发现,而修补漏洞成本高昂且耗时;因此,漏洞优先级排序是必须的,也是一个时间紧迫的挑战。目前使用的许多优先级排序指标,如 CVSS、EPSS、KEV 和 SSVC,各有优缺点,例如开放性、自动化程度、时间紧迫性、覆盖范围以及对专家输入的需求。在这项工作中,我们提出了 GitHub 流行度指标(GPM),这是一种完全开放、可公开计算的优先级排序指标,基于 GitHub 仓库中漏洞利用的流行度。我们利用 GitHub 功能,如星标数、分叉数和相关唯一用户数,创建了一个指标,用于指示 CVE 在不同时间框架内的流行度,既相对于当前时间,也相对于历史时间。我们将所提出的指标与各种现有的漏洞优先级排序指标以及已知被利用的漏洞进行比较,并证明它为防御者提供了切实的见解,识别出独特的 CVE 和现有方法中的不一致之处。GPM 已集成到 EPSS 版本 5 中。注意:基于这项工作的一项演示已被 ACM 计算机与通信安全会议(CCS)2026 的演示轨道接收。
英文摘要
Attackers can compromise multiple systems with a single vulnerability, while defenders need to fix all security weaknesses in their systems. This asymmetry puts defenders at a disadvantage. Security vulnerabilities are found at an alarming rate, and patching vulnerabilities is costly and time-consuming; thus, vulnerability prioritization is a must and a time-critical challenge. Many prioritization metrics, such as the CVSS, EPSS, KEV, and SSVC, are currently used, each with different pros and cons, such as openness, degree of automation, time-criticality, coverage, and need for expert input. In this work, we propose the GitHub Popularity Metric (GPM), a fully open, publicly computable prioritization metric based on the popularity of exploits in GitHub repositories. We use GitHub features such as the number of stars, forks, and related unique users to create a metric that indicates the popularity of CVEs across different time frames, both relative to the current time and historically. We compare the proposed metric with various existing vulnerability prioritization metrics and known exploited vulnerabilities and demonstrate that it provides tangible insights for defenders, identifying unique CVEs and inconsistencies in existing methods. The GPM was integrated into the EPSS version 5. \noindent\textbf{Note.} A demonstration based on this work has been accepted to the demo track of the ACM Conference on Computer and Communications Security (CCS) 2026.
发表机构
- Leiden University(莱顿大学)
机构由 AI 辅助整理,请以论文原文为准。