{"id":3601,"date":"2024-05-16T09:00:00","date_gmt":"2024-05-16T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/fall-of-national-vulnerability-database"},"modified":"2024-05-16T09:00:00","modified_gmt":"2024-05-16T14:00:00","slug":"the-fall-of-the-national-vulnerability-database","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/16\/the-fall-of-the-national-vulnerability-database\/","title":{"rendered":"The Fall of the National Vulnerability Database"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt87ff16389f98c1ed\/66461184ef007c2c9e307f2e\/Cybersecurity%281800%29_Stu_Gray_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the realm of cybersecurity, understanding your biggest vulnerabilities is essential. The National Institute of Standards and Technology (NIST) initially established the National Vulnerability Database (NVD) to provide a centralized hub for cybersecurity vulnerability intelligence \u2014 but did so under the assumption of rational actors making rational decisions and coming to rational conclusions.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While it was never meant to be the end-all-be-all solution, the NVD currently&nbsp;is&nbsp;the most widely used software vulnerability database in the world, with many scanners, analysts, and vendors depending on it daily to determine what software has been affected by a vulnerability. Yet,&nbsp;it recently was revealed that&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/nist-vuln-database-downshifts-prompting-questions-about-its-future\" rel=\"noopener\">NIST has not enriched vulnerabilities listed in the NVD since Feb. 12<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;\u2014 meaning anyone relying on these reports potentially has been at risk for months.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While it seems abrupt on the surface, this disruption is actually a systemic issue that has evolved over time. Since its inception nearly 25 years ago, three key factors have impacted the NVD&#8217;s ability to sufficiently classify security concerns that help the industry prioritize vulnerabilities \u2014 and what we&#8217;re experiencing now is the result.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Three Factors Affecting the NVD\">Three Factors Affecting the NVD<\/h2>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"1. Credit-Seeking Contributors\">1. Credit-Seeking Contributors<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Originally, vulnerabilities listed in the NVD hailed from seasoned researchers or well-established practitioners,&nbsp;and the assignment of a CVE&nbsp;(common vulnerabilities and exposures)&nbsp;served as acknowledgment for a job well done. However, as software security gained importance over time, an influx of aspiring researchers, often with scant experience, sought to leverage the NVD and CVE as springboards into the industry.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">They wanted the credit for new findings as an accolade of their contributions to the industry \u2014 similar to how a budding developer contributes to prominent open source projects. In its initial stages, this trend served as a viable r\u00e9sum\u00e9-building strategy. But, as more inexperienced researchers flooded the&nbsp;world with vulnerabilities, the quality of reports started to decline.&nbsp;&nbsp;<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Widespread Accessibility&nbsp;\">2. Widespread Accessibility&nbsp;<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the same time, the globalization of the Internet&nbsp;enabled researchers worldwide to partake in, and potentially impact, the industry in a meaningful way. It was no longer just a handful of seasoned researchers from select regions being credited with CVEs, and this second wave of people seeking recognition further increased the number of low-quality reports.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Along with the rise of inexperienced researchers, widespread accessibility opened the doors for&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/looted-ripe-credentials-for-sale-on-dark-web\" rel=\"noopener\">security vulnerabilities to be monetized on the Dark Web<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. While the payout might not be worth the risk for someone in an industrialized economy, it could be life-altering for someone in another part of the world. Rather than being credited for findings, some contributors opted to use vulnerabilities to commit a crime or sell the information to actors who would.&nbsp;&nbsp;<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Monetary Incentives\">3. Monetary Incentives<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In response&nbsp;to the above, bug bounties emerged as an incentive for researchers to disclose vulnerabilities to vendors rather than use them to do harm. The theory was that this would balance out the market and stop people from going over to the &#8220;dark side&#8221; of vulnerability detection.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Reporting vulnerabilities&nbsp;quickly became a numbers game. Rather than focusing on doing good work and gaining credit for it, this third cohort focused on pushing out as many reports as possible with as little effort as possible, hoping a few would hit a bounty payout so they could cash the check and move on.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Impact to Vendors&nbsp;\">Impact to Vendors&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Now, vendors face an onslaught of security disclosures stemming from the basic usage of free security tools that produce false positives and inaccurate, or irrelevant, findings. All of this noise has significantly increased the number of reports vendors must sift through daily, and the vast majority of them fail to provide any meaningful insight or exploitability. When everyone is spending so much time dealing with junk, there is less time to focus on quality research<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While this surge mirrors the proliferation of email scams in the late&nbsp;1990s and early 2000s, evolving from sophisticated schemes to boilerplate tactics as opportunists worldwide sought to capitalize on the financial gains, it&#8217;s crucial to acknowledge that this isn&#8217;t an indictment of individuals with limited access to education or technology. Everyone deserves an opportunity to carve out their niche and be duly compensated for their contributions, but the current state of affairs is a predictable outcome of the structured &#8220;rules of the game&#8221; we established.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Aftermath\">The Aftermath<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the number of CVEs being reported has dramatically increased, the CVE program worked toward a federated model by introducing a new program called Central Naming Authorities (CNA). This allowed organizations to to work through a process to become certified and trusted to issue CVEs directly. This allowed the program to scale to handle the new load.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In contrast, the NVD continued to be essentially a single threaded system where hired researchers would do extra research on each CVE to assign it a score (CVSS) and assign the affected software identification (Common Platform Enumeration, or CPE).&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The convergence of these factors created a flood of low-quality reports that has exacerbated&nbsp;researcher scaling&nbsp;challenges within the NVD program. The recent halt on enriched vulnerabilities underscores the imperative for refining existing frameworks to foster an environment where genuine contributions are recognized and noise is minimized.&nbsp;This is also an opportunity to rethink the structure of these systems. A federated model such as the CNA is designed to scale, and adding scoring and software identification to the CVEs they assign shouldn&#8217;t be a heavy lift.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">If we want to ensure the integrity and efficacy of our collective security efforts, the cybersecurity community must reassess its reliance on the NVD and adapt its processes to meet the evolving dynamics of vulnerability management.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/fall-of-national-vulnerability-database\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY In the realm of cybersecurity, understanding your biggest vulnerabilities<\/p>\n","protected":false},"author":12,"featured_media":3602,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3601","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?fit=1812%2C1063&ssl=1",1812,1063,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?fit=300%2C176&ssl=1",300,176,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?fit=640%2C376&ssl=1",640,376,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?fit=640%2C376&ssl=1",640,376,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?fit=1536%2C901&ssl=1",1536,901,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?fit=1812%2C1063&ssl=1",1812,1063,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?fit=1024%2C601&ssl=1",1024,601,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/the-fall-of-the-national-vulnerability-database.jpg?fit=1812%2C1063&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3601"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3601\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3602"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3601"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}