Wstg: WSTG Checklist v4.0 Likelihood rating reversal

Created on 1 May 2020  路  5Comments  路  Source: OWASP/wstg

What's the issue?
Describe the problem and why it should be fixed. Be concise and specific. Reference sections where appropriate.

It seems the Likelihood Factors for Threat-Agent-Factors.Skills-Required is reversed. Intuitively, it would get less likely as the skill required increases for a given vulnerability. So, if a vulnerability requires a Professional Pentester to exploit it, it's less likely to be exploited than if it can be exploited by any random Non-Technically Skilled actor. It seems like the list was written from the point-of-view of "who is exploiting" rather than "who is required to exploit".

How do we solve it?
Clearly describe the solution you'd like to see implemented.

Reverse the Skills required picklist on the Reference Tab of /checklists/WSTG-Checklist_v4.0.xlsx

To:
Skills required | 聽
-- | --
Select an option | 聽
Not Applicable [0] | 0
No technical skills [9] | 9
Some technical skills [6] | 6
Advanced computer user [5] | 5
Network and programming skills [3] | 3
Security penetration skills [1] | 1

Also update the help-text on the Calculator tab to something like: _How technically skilled do threat agents need to be to exploit this?_

Would you like to be assigned to this issue?
Check the box if you will submit a PR to fix this issue. Please read CONTRIBUTING.md.

  • [x] Assign me, please!

I could easily fix this if there isn't a v5 already in work by someone else.

revise

All 5 comments

Thanks for the offer, however we are probably going to remove this component. This particular detail resulted in many edit wars and issues on the old owasp wiki.

It actually is proper the way the values currently are, the problem is that skill isn't really part of likelihood. A more skilled attacker should result in greater risk. (Or the word skill is just the wrong word...)

I guess I would just add, I agree you can't put a likelihood on the skill of the actual attacker, but you can put a likelihood on the exploitability by assessing the skill required to attack.

@cBiscuit87 Does it happen that you'd like to update the checklist as we grow and move forward? Or might you have any other interests? :smile:

@ThunderSon I'd be happy to help wherever I can.

@cBiscuit87 Could you probably join us on slack in order to properly focus your contributions? Thanks :smile:

Was this page helpful?
0 / 5 - 0 ratings

Related issues

martinbydefault picture martinbydefault  路  10Comments

victoriadrake picture victoriadrake  路  4Comments

marevalo10 picture marevalo10  路  3Comments

ThunderSon picture ThunderSon  路  5Comments

kingthorin picture kingthorin  路  4Comments