Daniel Chiu
Daniel Chiu
Manager
TXOne Networks

Daniel Chiu works as a Threat Signature Research Team Manager at TXOne Networks.

Since 2013, he has focused on the improvement of DPI and the writing of DPI rules.

He currently leads the team to analyze network vulnerabilities and conduct research related to IPS rules and ICS protocols.

Interests: Studying network attack techniques and improving defense methods.

SPEECH
5/16 (Thu.) 15:45 - 16:15 4F 4A Supply Chain Cybersecurity Forum
A brief discussion on CVSS 4.0 and the evolution of vulnerability score assessment

On November 1, 2023, FIRST officially released CVSS 4.0. CVSS is not only one of the most important indicators in the information security industry, but also an important reference information for users when facing vulnerabilities.

This speech will introduce the concept of CVSS and the changes in CVSS 4.0. In the future, when viewers encounter CVSS scores, they will not just see them as numbers to better understand the meaning behind them. In addition, we will mention some details that are often overlooked in CVSS, such as: 50% of CVEs are CVSS 7 or above, only a few CVEs with high/severe severity are exploited, and the reasons why CVSS scores are generally high.

Finally, through simulation examples, the audience is guided to analyze a vulnerability, analyze various CVSS indicators, and use the CVSS calucator to calculate scores.