About 5.5% of identified vulnerabilities are used to carry out attacks

A team of researchers from Virginia Polytechnic Institute, along with companies Cyentia and RAND, released analyzed the risk assessment of various vulnerability remediation strategies. Studying 76,000 vulnerabilities identified from 2009 to 2018, they found that only 4,183 of them (5.5%) were exploited in actual attacks. This figure is five times higher than previously published forecasts, which estimated the number of exploited issues at approximately 1.4%.

Additionally, no correlation was found between the publication of exploit prototypes in the public domain and attempts to exploit vulnerabilities. Of all known instances of vulnerability exploitation, only in half the cases was a prototype exploit published in open sources prior to the issue. The absence of a prototype exploit does not deter attackers, who can create exploits themselves if necessary.

Other conclusions highlight the demand for exploiting primarily vulnerabilities classified with a high danger level according to CVSS. In almost half of the attacks, vulnerabilities with a severity of at least 9 were utilized.

The total number of exploit prototypes published during the reviewed period is estimated at 9,726. The data used in the research on exploits was sourced from
collections such as Exploit DB, Metasploit, D2 Security’s Elliot Kit, Canvas Exploitation Framework, Contagio, Reversing Labs, and Secureworks CTU.
Information on vulnerabilities was obtained from the database NIST NVD (National Vulnerability Database). Data about the instances of exploitation was summarized based on information from FortiGuard Labs, SANS Internet Storm Center, Secureworks CTU, Alienvault’s OSSIM, and ReversingLabs.

The study was conducted to determine the optimal balance between applying updates when any vulnerabilities are detected and addressing only the most dangerous issues. In the first case, high protection efficiency is ensured, but it requires significant resources for maintaining the infrastructure, which are mostly spent on fixing minor issues. In the second case, there is a great risk of missing a vulnerability that could be exploited for an attack. The study showed that when deciding to install an update that addresses a vulnerability, one should not rely on the absence of a published exploit prototype, and the likelihood of exploitation directly depends on the severity level of the vulnerability.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster