Loading... Loading...
Grenze Logo
GRENZE International Journal of Engineering and Technology Vol. 10 (2024), Issue 1

Vulnerability Scanning by CPE-CVE Matching

Authors

Amaravadi Adithya, Vansh Vyas, Madan Mohan, VA Aaswin, Sanjana Lanka

Abstract

Today organizations and institutions face a crucial challenge while managing their software vulnerabilities. The dynamic nature of security threats and constant software updates makes it difficult to have an efficient system to monitor and ensure software security by regularly checking for and installing the latest updates to fix potential vulnerabilities. All information regarding these updates and vulnerabilities is present in the official National Vulnerabilities Database (NVD). The challenge lies in efficiently locating software identifiers and updating the software inventory without constantly modifying the core algorithm. Through this Project, we aim to develop a CPE-CVE matching tool that aims to match CPE (Common Platform Enumeration) Identifiers to their respective CVE (Common Vulnerabilities and Exposures) Identifiers. This enables us to assess a software’s vulnerability to known threats and helps us build the bridge between specific vulnerabilities and affected software configurations. We have developed an algorithm to match CVEs based on CPE entries or identifiers dynamically. This reduces any human error that may occur while constantly updating the core algorithm and ensures the adaptability and effectiveness of the organization’s software ecosystem in managing vulnerabilities

Pages: 1289 - 1295