Andrey Kuleshov
Yandex Infrastructure
If you have a ticket, log in to watch the video
LoginThere are multiple databases and formats for storing vulnerabilities worldwide. Many of you are familiar with acronyms like CVE and CWE. Some have heard about NVD and OWASP, and others may even know how CVSS attack vectors are calculated. However, in the global programming community, there are now numerous databases and committees developing different formats, such as OSV, for better aggregation, search, and reporting of existing 1-day security problems. Sometimes, it is even challenging to keep track of all the new acronyms and standard updates that regularly appear.
In his talk, Andrey will provide an overview of existing formats, schemes, and repositories for vulnerabilities. He will share his experience in creating yet another new format for presenting and storing vulnerabilities called COSV. Additionally, he will discuss their experience in maintaining their vulnerability database, which has become the standard for the China Computing Federation (CCF).
Yandex Infrastructure
Independent developer