The CPE machine-readable software identifier used by the CVE program for two decades has been included in fewer than 50% of published CVEs, making it extremely difficult to identify vulnerable components. Last October, the CVE program accepted PURL as an alternative identifier; PURL is superior to CPE in many ways. But a much wider effort is needed for PURL to become the predominant software identifier in CVE records. The PURL Expansion Working Group will make that effort.
The PURL Expansion Working Group will accomplish its purpose in three phases.
Phase I will include three primary tasks. As these are all urgently needed, they will be accomplished simultaneously, if sufficient resources are available. Otherwise, they will be accomplished serially.
Develop a new PURL type, tentatively called SCID, that will enable commercial software products to be identified using PURL. Also, develop policies and procedures for creating and sharing PURLs based on the new type. This task will be accomplished collectively by the members of this working group.
Develop and test a tool to allow CVE Numbering Authorities (CNAs) to create new CVE records that contain a PURL. Currently, the primary tool available to create CVE records, Vuln-o-Gram, only supports CPE.
Develop and deliver basic training materials for CNAs interested in including PURLs in CVE records in the near future. The materials will address how to utilize the new tool to create those records. In order not to delay this training, the SCID type will not be discussed, since that is unlikely to be available for use until 6-9 months after Task 1 starts.
Create an email-based “CNA PURL help desk” to answer questions from CNAs about use of PURL in CVE records.
Key deliverables of this phase will include:
A. Type definition for the SCID type (coordinated with work currently being conducted by a PURL working group).
B. Documented policies and procedures for creating and sharing PURLs based on the SCID type.
C. Tool to create CVE records that contain PURL, tested by CNAs.
D. Videos and webinar(s) aimed at CNAs (but viewable by anyone) describing how to utilize the new tool to create a CVE record that contains a PURL.
E. CNA help desk.
Phase II will tentatively include five tasks. These will build on the work done in the first phase, but – assuming resource availability - they can all be started while the Phase I tasks are still in progress:
A. Recruit vulnerability database operators to support PURLs included in CVE records.
B. Recruit vulnerability scanning tool vendors to support PURLs included in CVE records.
C. Roll out PURL training (including SCID training) to the entire CVE community, including open source and commercial software developers, CNAs, vulnerability management service providers, and end users.
D. Conduct an end-to-end proof of concept for creating and utilizing CVE records that contain one or more PURLs.
E. Recruit app stores to create and roll out their own PURL types.
Key deliverables of this phase will include:
A. Regular reports on progress in recruiting vulnerability database operators to support CVE records that include a PURL, including challenges encountered.
B. Regular reports on progress in recruiting vulnerability scanning tool vendors to support CVE records that include a PURL, including challenges encountered.
C. PURL training, including SCID training, rolled out to the entire CVE community.
D. Documentation of results of end-to-end proof of concept for creating and utilizing CVE records that contain one or more PURLs, including PURLs based on the SCID type.
E. Regular reporting on progress in recruiting app stores to create and roll out their own PURL types, including challenges encountered.
Phase III will include at least two tasks:
Add PURLs to as many CVE records that do not contain CPE names as feasible.
Replace as many “broken” CPE names in existing CVE records with PURLs as possible. Broken CPE names includes names that do not follow the CPE specification, as well as other CPE names that do not appear to “point to” any specific product.
Key deliverables of this phase will include:
A. Regular reports on progress in adding PURLs to CVE records that do not contain CPE names, including discussion of problems encountered.
B. Regular reports on progress in replacing broken CPE names in existing CVE records with PURLs, including discussion of problems encountered.
Milestones for Phase I will include:
Start of meetings and definition of scope of work for subgroup focused on SCID
Completion of work by the above subgroup
Completion of first version of new tool for CNAs and recruitment of CNAs to test it
Completion of testing of the tool and delivery to CNAs
Start of delivery of basic training to CNAs
Completion of delivery of basic training to CNAs
We cannot currently identify milestones for Phase II or Phase III, but we will be able to do so 3-6 months before the start of work on each phase.
Depending on resource availability, we estimate the following timelines:
Phase I: 6-15 months
Phase II: 12-15 months
Phase III: 2-3 years
If adequate resources are available, we can work on any two or even all three phases simultaneously.