VulnScore: A deployed system for patch prioritization combining human input and temporal threat intelligence
摘要
Managing and remediating security vulnerabilities within complex IT environments is a continuous process. This process can often leave organizations with overwhelmed security teams and unresolved critical threats. Inefficient vulnerability management, particularly in prioritizing vulnerabilities, often leads to data breaches, financial losses, operational disruptions, regulatory noncompliance, and reputational harm. Traditional prioritization approaches largely rely on static factors such as CVSS scores, overlooking asset criticality and time-dependent exploitation risks. This paper introduces VulnScore, a deployed vulnerability prioritization system that derives a severity score—VulnScore Severity Rate—by integrating multiple crucial factors: Exploit Prediction Scoring System (EPSS), Vulners AI risk ratings, CVSS scores, and user-defined measures of system criticality. VulnScore is further embedded within Reconmap, an open-source penetration testing management platform, making it readily accessible to practitioners. Evaluation with 25 cybersecurity professionals was conducted through surveys and hands-on user testing. The major findings indicate that 92–96% of participants highlighted the ease of customization, integration, and responsiveness, while 88% agreed that VulnScore Severity Rate accurately reflected vulnerability severity. Performance testing showed near-real-time response (