- This event has passed.
Presentation: Beyond the CVSS: Leveraging XGBoost to Filter Vulnerability Noise (hybrid/Boston)
March 20 @ 11:00 am – 12:00 pm EDT
This talk will explore the intersection of machine learning and vulnerability management, focusing on how the XGBoost algorithm can be leveraged to predict the exploitability of Common Vulnerabilities and Exposures (CVEs). While frontier LLMs are currently revolutionizing vulnerability discovery — such as autonomously identifying zero-days in complex codebases — lightweight ML models remain the critical backbone for enterprise risk prioritization.
The presentation will cover the practical methodology of building an exploitability classifier, the statistical challenges of handling highly imbalanced security datasets where actual exploits are rare, and how these different AI approaches complement each other in a modern AppSec pipeline.
This talk is based on a 2024 research paper called Leveraging XGBoost Machine Learning Algorithm for Common Vulnerabilities and Exposures (CVE) Exploitability Classification.