Determining EPSS Score Thresholds for Prioritization | by Stephen Shaffer | Medium
As I observe the adoption and rhetoric around the Exploit Prediction Scoring System (EPSS), two themes that I see recurring are: The last bit is an intentional omission by the co-chairs, as it is not a problem that the model is designed to solve, nor do the co-chairs recommend the usage of “binning” without a clear understanding that the practice could result in information loss. However, industry adoption of EPSS may suffer if there is not at least some guidance on how to integrate it into existing vulnerability scoring or prioritization methodologies, including when to start caring about the score and/or percentile (hint: you should always care). Of course, organizations and vendors are welcome to decide on their thresholds for prioritization/categorization based on their risk tolerance or scoring system. Still, in practice, this may be even harder to determine than the exercise I’m about to perform here. I’ve seen entities vary widely in how they bin EPSS scores (with some even trea
Cybersecurity Threat Intelligence Data Science Machine Learning Vulnerability Management Determining EPSS Score Thresholds for Prioritization Stephen Shaffer 9 min read · Nov 5, 2023 -- 1 Listen Share Press enter or click to view image in full size As I observe the adoption and rhetoric around the Exploit Prediction Scoring System (EPSS), two themes that I see recurring are: An unfamiliarity with what EPSS actually is; and Unclear guidance on how to determine score thresholds for prioritization. The last bit is an intentional omission by the co-chairs, as it is not a problem that the model is
Explore this link on the map →related reading
- Mediumstephenshaffer.io
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Claude Mythos Preview System Cardwww-cdn.anthropic.com
- Measuring LLMs’ ability to develop exploits \ Anthropicred.anthropic.com
- FIRST Mid-Year Vulnerability Forecast Confirms Historic Surge, Projects ~66,000 CVEs in 2026first.org
- Measuring LLMs' impact on N-day exploits \ Anthropicred.anthropic.com
- Doing EA Better — EA Forumforum.effectivealtruism.org
- The bogus CVE problem [LWN.net]lwn.net
- AuditAgentauditagent.nethermind.io
- Claude Mythos Preview System Cardwww-cdn.anthropic.com
- EVMBench Leaderboard — AI Smart Contract Auditorstestmachine.ai
- Center for Responsible, Decentralized Intelligence at Berkeleyrdi.berkeley.edu