科研速览 · Science Skim继续刷下去 · Keep skimming →
2026-07-31· Computer science

Vulnerability Discovery and Exposure Reduction

Jason Edwards

原始摘要(英文原文)· Original abstract
Vulnerability discovery and exposure reduction depend on turning imperfect visibility into reliable operations that consistently drive risk down. This chapter explains how scanning approaches differ in operational fit, from external and internal scanning to credentialed validation, agent based telemetry, and passive discovery. It emphasizes that the goal is actionable visibility, not raw finding volume, and that method selection must reflect safety, reachability, authentication depth, and scheduling constraints. The chapter then focuses on coverage gaps and blind spot management as an ongoing control problem. Readers learn why inventory drift, reachability loss, authentication degradation, and method boundaries can create false certainty, and how to measure coverage using signals such as in scope, reachable, authenticated, and high confidence. It also covers how to identify and validate external exposure and high-risk services from an attacker perspective, tying discovery to ownership, monitoring readiness, and remediation pathways. Finally, the chapter details how to validate findings and reduce noise so vulnerability data is trusted and operationally useful. It addresses managing false positives and repeated findings through evidence retention, normalization, root-cause correction, and disciplined exception handling. It explains how discovery should coordinate with change management and how vulnerabilities must be tracked across asset lifecycles, including ephemeral compute. The chapter concludes with governed AI workflows for deduplication, clustering, and verification assistance that reduce triage workload while preserving human-in-the-loop approval boundaries and auditability.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Vulnerability Discovery and Exposure Reduction — 科研速览 Science Skim