Pith. sign in

REVIEW 3 cited by

Enhancing Vulnerability Prioritization: Data-Driven Exploit Predictions with Community-Driven Insights

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2302.14172 v2 pith:EPQLKLBM submitted 2023-02-27 cs.CR

classification cs.CR
keywords vulnerabilityexploitscoringvulnerabilitiesavailabledata-drivenepssexploitation
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

The number of disclosed vulnerabilities has been steadily increasing over the years. At the same time, organizations face significant challenges patching their systems, leading to a need to prioritize vulnerability remediation in order to reduce the risk of attacks. Unfortunately, existing vulnerability scoring systems are either vendor-specific, proprietary, or are only commercially available. Moreover, these and other prioritization strategies based on vulnerability severity are poor predictors of actual vulnerability exploitation because they do not incorporate new information that might impact the likelihood of exploitation. In this paper we present the efforts behind building a Special Interest Group (SIG) that seeks to develop a completely data-driven exploit scoring system that produces scores for all known vulnerabilities, that is freely available, and which adapts to new information. The Exploit Prediction Scoring System (EPSS) SIG consists of more than 170 experts from around the world and across all industries, providing crowd-sourced expertise and feedback. Based on these collective insights, we describe the design decisions and trade-offs that lead to the development of the next version of EPSS. This new machine learning model provides an 82\% performance improvement over past models in distinguishing vulnerabilities that are exploited in the wild and thus may be prioritized for remediation.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Forecasting the risk of software choices: A model to foretell security vulnerabilities from library dependencies and source code evolution

    cs.SE 2024-11 reject novelty 6.0 of 10

    A time dependency tree model combines dependency graphs, source-code version history, and fitted CVE disclosure curves to estimate the probability that a project faces a CVE within a future window.

  2. Modeling Local Exploit Hazard - A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency

    cs.CR 2026-07 conditional novelty 5.0 of 10

    A Bayesian control-effectiveness layer plus exponential/Weibull survival conversion turns EPSS-style probabilities into additive local exploit hazard rates for remediation ranking.

  3. The Impact of AI on the Cyber Offense-Defense Balance and the Character of Cyber Conflict

    cs.CR 2025-04 accept novelty 4.0 of 10

    After reviewing 66 arguments about cyber conflict, the paper concludes AI's effect on the offense-defense balance is mixed and lists 44 pathways through which AI could change cyber conflict.

Pith tools