Initial release: vulnerability_class baseline + comprehensive 8-oracle-path leakage diagnostic on CYB009 sample
e520bf1 verified | { | |
| "feature_names": [ | |
| "cvss_base_score", | |
| "epss_score_final", | |
| "exploitation_occurred_flag", | |
| "zero_day_flag", | |
| "cisa_kev_flag", | |
| "supply_chain_propagation_flag", | |
| "compensating_control_flag", | |
| "false_positive_flag", | |
| "remediation_success_flag", | |
| "sla_compliance_flag", | |
| "scanner_coverage", | |
| "patch_mgmt_maturity", | |
| "mean_time_to_remediate_days", | |
| "sla_critical_days", | |
| "sla_high_days", | |
| "sla_medium_days", | |
| "internet_exposed_flag", | |
| "sbom_depth_score", | |
| "log_epss", | |
| "is_high_cvss", | |
| "exposure_severity_composite", | |
| "risk_flag_count", | |
| "epss_x_base", | |
| "severity_class_critical", | |
| "severity_class_high", | |
| "severity_class_low", | |
| "severity_class_medium", | |
| "asset_type_api_gateway", | |
| "asset_type_cloud_vm", | |
| "asset_type_container_workload", | |
| "asset_type_database_server", | |
| "asset_type_endpoint_workstation", | |
| "asset_type_iot_firmware_device", | |
| "asset_type_network_service", | |
| "asset_type_ot_ics_controller", | |
| "asset_type_saas_integration", | |
| "asset_type_server_on_premises", | |
| "asset_type_supply_chain_dependency", | |
| "asset_type_web_application", | |
| "criticality_tier_critical", | |
| "criticality_tier_high", | |
| "criticality_tier_low", | |
| "criticality_tier_medium", | |
| "environment_type_edge_iot_fleet", | |
| "environment_type_hybrid_cloud", | |
| "environment_type_on_premises_datacenter", | |
| "environment_type_ot_ics_network", | |
| "environment_type_public_cloud_aws", | |
| "environment_type_public_cloud_azure", | |
| "environment_type_public_cloud_gcp", | |
| "environment_type_saas_dependent", | |
| "os_family_android_iot", | |
| "os_family_embedded_rtos", | |
| "os_family_freebsd", | |
| "os_family_linux", | |
| "os_family_macos", | |
| "os_family_windows" | |
| ], | |
| "numeric_features": [ | |
| "cvss_base_score", | |
| "epss_score_final", | |
| "exploitation_occurred_flag", | |
| "zero_day_flag", | |
| "cisa_kev_flag", | |
| "supply_chain_propagation_flag", | |
| "compensating_control_flag", | |
| "false_positive_flag", | |
| "remediation_success_flag", | |
| "sla_compliance_flag", | |
| "scanner_coverage", | |
| "patch_mgmt_maturity", | |
| "mean_time_to_remediate_days", | |
| "sla_critical_days", | |
| "sla_high_days", | |
| "sla_medium_days", | |
| "internet_exposed_flag", | |
| "sbom_depth_score", | |
| "log_epss", | |
| "is_high_cvss", | |
| "exposure_severity_composite", | |
| "risk_flag_count", | |
| "epss_x_base" | |
| ], | |
| "categorical_levels": { | |
| "severity_class": [ | |
| "critical", | |
| "high", | |
| "low", | |
| "medium" | |
| ], | |
| "asset_type": [ | |
| "api_gateway", | |
| "cloud_vm", | |
| "container_workload", | |
| "database_server", | |
| "endpoint_workstation", | |
| "iot_firmware_device", | |
| "network_service", | |
| "ot_ics_controller", | |
| "saas_integration", | |
| "server_on_premises", | |
| "supply_chain_dependency", | |
| "web_application" | |
| ], | |
| "criticality_tier": [ | |
| "critical", | |
| "high", | |
| "low", | |
| "medium" | |
| ], | |
| "environment_type": [ | |
| "edge_iot_fleet", | |
| "hybrid_cloud", | |
| "on_premises_datacenter", | |
| "ot_ics_network", | |
| "public_cloud_aws", | |
| "public_cloud_azure", | |
| "public_cloud_gcp", | |
| "saas_dependent" | |
| ], | |
| "os_family": [ | |
| "android_iot", | |
| "embedded_rtos", | |
| "freebsd", | |
| "linux", | |
| "macos", | |
| "windows" | |
| ] | |
| }, | |
| "label_to_int": { | |
| "auth_access_control": 0, | |
| "cryptographic_failure": 1, | |
| "information_disclosure": 2, | |
| "injection_family": 3, | |
| "logic_flaw": 4, | |
| "memory_corruption": 5, | |
| "misconfiguration": 6, | |
| "supply_chain_weakness": 7 | |
| }, | |
| "int_to_label": { | |
| "0": "auth_access_control", | |
| "1": "cryptographic_failure", | |
| "2": "information_disclosure", | |
| "3": "injection_family", | |
| "4": "logic_flaw", | |
| "5": "memory_corruption", | |
| "6": "misconfiguration", | |
| "7": "supply_chain_weakness" | |
| }, | |
| "outcome_leak_excluded": [ | |
| "time_to_exploit_days", | |
| "time_to_remediate_days", | |
| "patch_lag_days", | |
| "risk_score_composite", | |
| "exploit_maturity_final", | |
| "cvss_temporal_score_final" | |
| ] | |
| } |