Git Product home page Git Product logo

vulntology's Introduction

Gitter Google group : Vulntology Dev

NIST Vulnerability Data Ontology

The Vulntology is a project created to characterize vulnerabilities and provide a granular and intuitive structure for that information. This repository is a location to support community development of the NIST Vulnerability Data Ontology, or Vulntology.

Project Scope

The Vulntology is intended to provide characterization details about how a vulnerability can be exploited, what the impact of that exploit will be, and what mitigating factors can make exploitation difficult. These details are provided in the context of a given attack scenario, which may differ in characteristics from other scenarios for the same vulnerability.

The Vulntology is not intended to be a general purpose format for describing vulnerability information. Instead, the Vulntology is intended to be a drop-in replacement for a vulnerability description. The Vulntology project will avoid duplicating work in other formats to the greatest extent possible. Due to the relational approach used, the Vulntology may provide some overlapping details as a means to define a given scenario, such as affected product information.

Goals

  • To standardize the description of vulnerabilities through structured characterization formatting.
  • To enable automated scoring agnostic of any particular system.
  • To improve the level of detail in provided information for the purpose of assisting with defense while minimizing increased risk from attacks.
  • To allow for easier vulnerability information sharing across language barriers

How to Help

We are currently looking for assistance from organizations and people within the vulnerability management community. For those interested please refer to the Contributing page.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.