mal-lang / coreLang

A probabilistic attack simulation language for the (abstract) IT domain
https://mal-lang.org/coreLang/
Other
11 stars 13 forks source link

Evaluate if we want to integrate exploitability reports into the SoftwareVulnerability defences #68

Open andrewbwm opened 3 years ago

andrewbwm commented 3 years ago

We may wish to integrate reports(e. g., https://www.cisa.gov/known-exploited-vulnerabilities-catalog) into the values assigned to the defences on the SoftwareVulnerability asset, such as highComplexityExploitRequired.

The debate so far has not come to any conclusions and was postponed for after the v1.0 release.