This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Enabling Effective Vulnerability Prioritization: Leveraging Ensemble LLMs in the Wake of NIST NVD Challenges

Download resources

About this session

Phimm Phonpaseuth, who leads cyber risk engineering at Balbix after years at Palo Alto Networks and Symantec, opens by noting that NIST's 2024 budget cuts left roughly 90 percent of newly reported CVEs unenriched, and frames vulnerability management as fundamentally a scale and complexity problem: a typical Fortune 500 company carries around 15 million open CVEs and exposures across a trillion possible attack paths, generating about 0.2 petabytes of signal a day, far beyond what any human team can review, while exploit time for actively exploited vulnerabilities has shrunk to about five days. He argues AI's value is specialized computation at scale plus a shared quantitative language, likelihood times impact, that lets security teams talk to boards and CFOs in dollars instead of jargon. He walks through Balbix's approach: ensembles of large language models and classical models vote on device categorization, infer likely CVEs from asset attributes without a scan, and map CVE descriptions to MITRE ATT&CK techniques where NVD provides no mapping. A Q&A covers where AI should replace manual computation versus leave room for human judgment, and how to build a cost-benefit case for the tooling.

In March 2024, the cybersecurity community faced significant challenges with the National Vulnerability Database (NVD) maintained by NIST. The NVD's inability to enrich vulnerabilities left many teams struggling to prioritize their remediation efforts effectively. However, with gaps in vulnerability data, organizations were left exposed to potential threats. Recognizing the necessity for a robust vulnerability enrichment system, we embarked on a journey to leverage artificial intelligence (AI) to address this challenge. Initially, we used a single large language model (LLM), but it proved cost-prohibitive. However, through iterative refinement, we developed an ensemble of LLMs that work together to enrich vulnerabilities. Our ensemble approach harnesses the collective power of LLMs to analyze vast amounts of IT and security data, including tens of thousands of vendor and product web pages, to extract and enrich vulnerabilities. Furthermore, we incorporate insights from threat intelligence and internal security tools to understand the impact of a particular vulnerability. In this presentation, we explain the methodologies and techniques used to construct and deploy our ensemble of LLMs. We share insights from our experiences and offer practical guidance for organizations seeking to enhance their vulnerability management program in the face of evolving threats and unreliable data sources.

Key takeaways

  • Do not assume NVD scores cover your exposure: after 2024 funding cuts about 90% of new CVEs go unenriched, and non-CVE exposures like cloud misconfigurations were never scored by NVD at all.
  • Prioritize patching by exploit likelihood, not just severity; actively exploited vulnerabilities are being weaponized in about five days versus roughly 68 days for the rest.
  • Use AI for low-value, high-volume computation (device categorization, CVE inference from asset attributes, mapping CVEs to MITRE ATT&CK) and reserve human judgment for architecture and prioritization calls.
  • Translate cyber risk into a likelihood-times-impact dollar figure so boards and CFOs can compare it directly to other business risks instead of parsing technical severity scores.
  • Before buying AI-powered risk tooling, run the cost-benefit case explicitly: weigh the tool's price against measurable gains in visibility, mean time to remediate and reduced manual analysis.

Speakers

Phimm Phonpaseuth
Phimm Phonpaseuth
VP, Cyber Risk Engineering. · Balbix
Phimm Phonpaseuth is a seasoned business and technology professional with over 22 years of diverse experience in the IT industry. Currently serving as the VP of WW Sales Engineering at Balbix, he specializes in cyber risk management dedicated to… Read moreRead less

Phimm Phonpaseuth is a seasoned business and technology professional with over 22 years of diverse experience in the IT industry. Currently serving as the VP of WW Sales Engineering at Balbix, he specializes in cyber risk management dedicated to driving technical solutions and contributing to industry innovation. Previously, Phimm held key roles at Symantec, Securit.AI, and Palo Alto Networks as a Solutions Architect, where he led cloud solutions architecture in Canada. He lives with his family in Toronto.

Resources

Tags

More from GoSec 2024

Also from Phimm Phonpaseuth

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.