A Vulnerability Database Should Not Be About Vulnerabilities
Offered By: Linux Foundation via YouTube
Course Description
Overview
Explore a thought-provoking conference talk that challenges conventional thinking about vulnerability databases. Delve into the current state of these databases and uncover the "Telephone Game Problem" affecting data integrity. Examine the importance of trust and the concept of putting packages first. Investigate why focusing on vulnerable code is crucial and learn about tools and data sources for effective vulnerability management. Discover techniques for aggregating, correlating, and refining data across multiple levels. Address challenges such as growth packages, missing packages, and duplicated data. Gain insights into future plans for improving vulnerability databases and enhancing overall cybersecurity practices.
Syllabus
Introduction
Agenda
State of Vulnerability Databases
Telephone Game Problem
Trust
Package First
Why vulnerable code
Tools
Data Source
Aggregate Correlate
Multilevel Refinement
Growth Packages
Missing Packages
Duplicated Data
Other Issues
Future Plans
Outro
Taught by
Linux Foundation
Tags
Related Courses
Pattern-Oriented Software Architectures: Programming Mobile Services for Android Handheld SystemsVanderbilt University via Coursera Engineering Maintainable Android Apps
Vanderbilt University via Coursera Software Design as an Element of the Software Development Lifecycle
University of Colorado System via Coursera Secure Software Development
Pluralsight Secure Software Concepts for CSSLPĀ®
Pluralsight