Predicting the exploitability of vulnerabilities

Everyday, hundreds of new vulnerabilities are discovered and disclosed to the users of the systems they affect. The sheer volume of vulnerabilities makes it difficult, if not impossible, for system administrators to rapidly address every vulnerability. Furthermore, research shows that only 5% of vulnerabilities are eventually exploited. This situation brings about a need to prioritize some vulnerabilities over others, with the vulnerabilities most likely to be exploited treated as priorities. Existing approaches to these vulnerabilities are inadequate because they rely on information that may be unavailable at the time the vulnerability is publicized. In this project, we endeavor to develop a vulnerability prioritization algorithm that only relies upon information available on the day the vulnerability is disclosed, and fills in missing data using ML.

Faculty Supervisor:

Raphaël Khoury

Student:

Partner:

Secureworks

Discipline:

Computer science

Sector:

Professional, scientific and technical services

University:

Université du Québec en Outaouais

Program:

Accelerate

Current openings

Find the perfect opportunity to put your academic skills and knowledge into practice!

Find Projects