NIST Explores AI for National Vulnerability Database
Summary
The U.S. National Institute of Standards and Technology, or NIST, is asking how artificial intelligence can improve the National Vulnerability Database. The agency seeks industry advice on automating stages of vulnerability management. NIST runs the National Vulnerability Database, which is under pressure from the sudden growth in known software flaws. A request for information from the agency asks for recommendations on AI's role in identifying, validating, disclosing, prioritizing, and remediating software and system vulnerabilities. New reports are coming into the database more quickly than NIST can respond. The public comment request will last for 60 days. This is part of an effort to reevaluate the agency's role in enriching entries into the exploit catalog. NIST intends to support a "future-ready vulnerability management ecosystem that is continuous, contextual and automated." The agency once provided standardized vulnerability enrichment to all Common Vulnerabilities and Exposures, or CVEs. However, the surge in vulnerability submissions has pushed it to only enrich CVEs meeting certain criteria. NIST now processes actively exploited vulnerabilities, flaws in software used by the federal government, or vulnerabilities in critical assets. NIST's list of questions for the technology community shows an interest in using AI to accelerate a process falling behind. The agency says the "inadequacies of traditional vulnerability management approaches" are increasingly apparent, and AI presents an opportunity to transform the ecosystem. This matters because improving vulnerability management helps protect against real-world cybersecurity threats.
This is an AI-generated audio summary. Always check the original source for complete reporting.