DHS未能续约,漏洞赏金计划即将迅速结束
CVE program faces swift end after DHS fails to renew contract

原始链接: https://www.csoonline.com/article/3963190/cve-program-faces-swift-end-after-dhs-fails-to-renew-contract-leaving-security-flaw-tracking-in-limbo.html

美国国土安全部(DHS)可能削减对MITRE CVE项目的资金,这将威胁到全球漏洞管理生态系统。主要后果包括:漏洞协调员(CNA)将无法快速发布漏洞信息;本已捉襟见肘的国家漏洞数据库(NVD)将面临更大的分析积压。依赖CVE/NVD获取漏洞情报的公司将面临严重中断,需要寻找替代来源。这将影响维护自身漏洞数据库的组织以及中国和俄罗斯等国的国家漏洞数据库,可能导致可用情报下降。依赖免费CVE/NVD数据的国家和地区CERT也将受到负面影响。这些变化,可能是由政府削减开支造成的,将给全球漏洞管理项目带来“迅速而剧烈的痛苦”。

合同续签失败威胁着CVE项目,这是一个至关重要的网络安全资源。美国国家标准与技术研究院(NIST)维护的国家漏洞数据库(NVD)的资金削减已经持续了一年多,导致漏洞积压日益严重。虽然CVE项目由MITRE管理,但NIST的NVD通过评分和分析丰富了CVE数据,使其成为广泛依赖的资源。 安全界担心可能会有越来越多的漏洞得不到解决,一些漏洞已经在野外被利用。美国网络安全与基础设施安全局(CISA)正在启动“Vulnrichment”项目,为CVE添加更多信息。NVD和CVE项目几年来一直面临着积压和资金问题,大多数安全厂商要么对及时提供漏洞信息守口如瓶(因为这可能会降低他们自身的竞争优势),要么试图推销他们自己的替代风险优先级评分。 诸如合作联盟之类的替代方案正在考虑中,但尚未实现。这种中断引发了人们对美国失去其技术和科学领导地位以及潜在的安全风险增加的担忧。

原文

“First, the federated model and CVE Numbering Authorities (CNA) can no longer assign IDs and send info to MITRE for quick publication. Second, all of that is the foundation for the National Vulnerability Database (NVD), which is already beyond struggling, with a backlog of over 30,000 vulnerabilities and the recent announcement of over 80,000 ‘deferred’ (meaning will not be fully analyzed by their current standards).”

Martin added, “Third, every company that maintains ‘their own vulnerability database’ that is essentially lipstick on the CVE pig will have to find alternate sources of intelligence. Fourth, national vulnerability databases like China’s and Russia’s, among others, will largely dry up (Russia more than China). Fourth [sic], hundreds, if not thousands, of National / Regional CERTs around the world, no longer have that source of free vulnerability intelligence. Fifth [sic], every company in the world that relied on CVE/NVD for vulnerability intelligence is going to experience swift and sharp pains to their vulnerability management program.”

It’s unclear what led to DHS’s decision to end the contract after 25 years of funding the highly regarded program. The Trump administration, primarily through Elon Musk’s Department of Government Efficiency initiative, has been slashing government spending across the board, particularly at the Cybersecurity and Infrastructure Security Agency (CISA), through which DHS funds the MITRE CVE program.

联系我们 contact @ memedata.com