{"id":3873,"date":"2024-06-04T08:00:00","date_gmt":"2024-06-04T13:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain"},"modified":"2024-06-04T08:00:00","modified_gmt":"2024-06-04T13:00:00","slug":"nist-commits-to-vulnerability-plan-but-researchers-concerns-remain","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/04\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain\/","title":{"rendered":"NIST Commits to Vulnerability Plan, But Researchers&#8217; Concerns Remain"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltd1c61866192805f3\/665e6c28836b207ec03ed3c7\/stressedITtech-PantherMediaGmbH-AlamyStockPhoto.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More than 100 days after the National Vulnerability Database all but ceased validating the severity of vulnerability reports, the US National Institute of Standards and Technology has come up with a plan to get back on track.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">On May 29, NIST announced that the agency had awarded a contract to support future processing to &#8220;allow us to return to the processing rates we maintained &#8230; within the next few months&#8221; and has partnered with the Cybersecurity and Infrastructure Security Agency (CISA) to reduce the backlog by Sept. 30, the end of the US government&#8217;s fiscal year. NIST is also working on updating technology and modifying its process to handle the greater number of vulnerabilities disclosed every year, the agency <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nist.gov\/itl\/nvd\" rel=\"noopener\">said in a status update<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The key to taming the backlog will be to take a multipronged approach and work with both public and private sector participants to satisfy future needs, says Matt Scholl, chief of the Computer Security Division at NIST&#8217;s Information Technology Lab.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Once we have restored our capacity, NIST will continue working with the CVE Board, the CNAs, FIRST, and the vulnerability management community to update any needed data specifications, coordinate transitions to new specs, and identify areas for improvement,&#8221; he says. &#8220;We plan to identify processes that will result in a &#8216;better NVD&#8217; to include the use of automation, tooling, participation, and updated standards and data specifications.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The origin of the problem that led to the bottleneck, however, remains largely a mystery. In mid-February, NIST, which maintains the National Vulnerability Database, all but stopped processing new vulnerabilities, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/readme.synack.com\/nist-vulnerability-bottleneck-underscores-fragility-of-software-security\" rel=\"noopener\">citing a &#8220;perfect storm&#8221; of challenges<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The agency typically enriches new vulnerabilities reported in the Common Vulnerabilities and Exposures (CVE) process <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/general\/cve-process\" rel=\"noopener\">with additional information<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, or by verifying existing information such as the product affected; assigning a Common Weakness Enumeration (CWE) identifier; and calculating impact and exploitability metrics.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Fast-Growing Flaws Meet Slow-Changing Government\">Fast-Growing Flaws Meet Slow-Changing Government<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NIST faces an exponentially growing problem. Following the removal of bottlenecks in the process of assigning Common Vulnerabilities and Exposures (CVE) identifiers in 2017, the number of vulnerabilities disclosed each year with an associated identifier has taken off. In 2016, less than 6,500 vulnerabilities were disclosed. The following year, that jumped to more than 14,600, and it has grown every year after that. This year, the tide of vulnerabilities is on track to surpass 36,000.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The quickly increasing flood of issues has become an issue not just for defenders who want to apply necessary software patches, but for the threat-information providers that want to make sense of the deluge, says Josh Bressers, vice president of security at Anchore.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The way vulnerabilities used to work isn&#8217;t how they work anymore,&#8221; he says. &#8220;The sheer volume of CVEs, the amount of automated tooling, and the number of organizations paying attention is larger than anyone could have imagined 20 years ago.&#8221;<\/span><\/p>\n<div readability=\"10\"><img data-recalc-dims=\"1\" decoding=\"async\" data-testid=\"content-image\" data-component=\"image\" class=\"ContentImage-Image ContentImage-Image_align_left\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain-1.jpg\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain-1.jpg?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Bar chart of vulnerabilities analyzed\" title=\"Bar chart of vulnerabilities analyzed\"><\/p>\n<p class=\"ContentImage-Link\">As monthly vulnerability counts climb, the NVD remains behind. Source: Robert Lemos, data from the NVD dashboard<\/p>\n<\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NIST had been keeping up \u2014 until suddenly it wasn&#8217;t. The agency has only processed 26% of the vulnerabilities disclosed so far this year, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/nvd.nist.gov\/general\/nvd-dashboard\" rel=\"noopener\">according to data from its dashboard<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. No one factor \u2014 neither the quickly growing workload nor a lack of people \u2014 led to the stoppage of work on reviewing vulnerability ratings, says NIST&#8217;s Scholl.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;It is not one or the other, but a combination of many pressures,&#8221; he says. &#8220;Reductions in resources coupled with the steady increase in vulnerabilities were certainly the main causes for this interruption.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NIST plans to work with the community to improve the process, and explicitly mentioned working with CISA. Two months ago, CISA launched a project to add metadata to vulnerability information, dubbed <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/github.com\/cisagov\/vulnrichment\" rel=\"noopener\">CISA Vulnrichment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The project aims to enrich vulnerability information with data from the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/stakeholder-specific-vulnerability-categorization-ssvc\" rel=\"noopener\">Stakeholder-Specific Vulnerability Categorization (SSVC)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> analysis process.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Between the two efforts, the government agencies could come up with a workable solution, says Kaylin Trychon, vice president of marketing at Chainguard, a supply chain security firm. CISA has already triaged about 1,300 vulnerabilities (although nearly 18,000 vulnerabilities have been disclosed) and assigned CVEs since the beginning of 2024.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;When NIST is up and running, the hope is this data can make the process for triaging and scoring CVEs faster to burn through the backlog,&#8221; she says. &#8220;Again, this is another temporary solution, but it is encouraging to see the nation&#8217;s cybersecurity arm jumping in with resources to help chip away at the larger problem.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Trychon and other cybersecurity industry professionals <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/docs.google.com\/document\/d\/1y6JXhh52b1OMxLMQyl_WH0R2-85iYEBzjSm_fhv8-GY\/edit\" rel=\"noopener\">sent a letter to Congress<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in mid-April warning of a crisis in cybersecurity and urging them to restore the NVD to full operation. Whether that pressure helped NIST free up the resources is unclear.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet Trychon wonders if the current effort will be enough. The government needs to raise the priority of the NVD, and treat it as an essential service and as critical infrastructure, she says. Current discussions have suggested that a nonprofit foundation could be established through a public-private partnership.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In theory, this funding source would ensure that critical programs, such as the NVD, remain resourced appropriately while giving a clear path for the private sector to contribute to the continuity of operations,&#8221; she says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Anchore&#8217;s Bressers remains concerned that short-term efforts may not be enough and that long-term efforts will falter.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Everyone says how important and critical vulnerability information is, but I think the amount of interest and investment tells a different story,&#8221; he says. &#8220;It is very difficult and thankless work.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>More than 100 days after the National Vulnerability Database all<\/p>\n","protected":false},"author":12,"featured_media":3874,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3873","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/nist-commits-to-vulnerability-plan-but-researchers-concerns-remain.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3873"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3873\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3874"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}