Sign in

Stephen Shaffer

@t0sche.infosec.exchange.ap.brid.gy
4 followers 1 following 6 posts

Engineering risk model-informed decisions. Writing at stephenshaffer.io #infosec #risk #elm 🌉 bridged from ⁂ infosec.exchange/@t0sche, follow @ap.brid.gy to interact

PostsRepliesMedia
Stephen Shaffer @t0sche.infosec.exchange.ap.brid.gy · 17/08/2026
Source paper: arxiv.org/abs/2607.24618
arxiv.org
Modeling Local Exploit Hazard - A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency
This paper presents a local exploit hazard model : a Bayesian framework that converts the global probabilities produced by an exploit likelihood model (ELM), such as the Exploit Prediction Scoring System (EPSS), into a daily exploit hazard rate for an organization's own assets. The model measures the exploit-prevention effectiveness of deployed controls as a probability distribution. That distribution is seeded from a subject-matter-expert opinion pool and updated through Beta-Binomial inference from telemetry, breach-and-attack simulation, or penetration testing, then applied to ELM scores by attack-vector alignment. The resulting per-vulnerability exploitation likelihoods are converted into hazard rates using standard survival-analysis techniques, supporting both a constant exponential hazard and a Weibull hazard whose shape parameter, calibrated from Known Exploited Vulnerabilities catalog timing, captures the empirical decay of exploitation risk as a vulnerability ages. Because hazards are additive under independence, per-vulnerability rates aggregate by summation up to host, network, business unit, and organization. Candidate remediation actions are simulated and ranked by projected hazard reduction, giving defenders a defensible, quantitative basis for prioritization under fixed capacity. Future work includes extensions for incident likelihood and financial loss modeling.
010
Stephen Shaffer @t0sche.infosec.exchange.ap.brid.gy · 17/08/2026
RE: infosec.exchange/@adulau/1170761984… Couldn’t have imagined a better way for this idea to be picked up and implemented. #Kudos to @circl, @adulau, and @cedric 👏🫶
102
Stephen Shaffer @t0sche.infosec.exchange.ap.brid.gy · 01/11/2025
#EPSS gives us a lens into global exploit pressure. But to further understand our vulnerability risk posture, we need to adjust that pressure through the lens of our own controls — and their measured effectiveness. In my latest blog, I show you how to take EPSS asset-level exploit likelihoods […]
infosec.exchange
Original post on infosec.exchange
000
Reposted by Stephen Shaffer
Simon Zerafa @simonzerafa.infosec.exchange.ap.brid.gy · 26/03/2025
@adamshostack Also:
003
Stephen Shaffer @t0sche.infosec.exchange.ap.brid.gy · 14/03/2025
‼️ On Monday, March 17th 2025, EPSS v4 will be released and replace the current version (v3). ❓ What does this mean? The model is being updated and expanded to include more data sources and is more accurate than v3. The Coverage/Efficiency Curve […] [Original post on infosec.exchange]
000
Stephen Shaffer @t0sche.infosec.exchange.ap.brid.gy · 11/03/2025
@cgudrian @GossiTheDog vulncheck.com/nvd2
vulncheck.com
NVD++
A reliable service providing access from a single source to NIST NVD (enriched w/ VulnCheck CPE) and Mitre CVElist
001
Stephen Shaffer @t0sche.infosec.exchange.ap.brid.gy · 07/03/2025
Happy to announce I’ll be speaking #VulnCon25 next month. I’ll be chatting about Asset EPSSg, which is a concept that orients you to the exploitation exposure risk at the asset level, rather than the CVE level. More info here […] [Original post on infosec.exchange]
000