NIST Seeks Feedback on Modernizing NVD for AI Era

▼ Summary
– NIST published an RFI on August 12 seeking stakeholder input on modernizing the National Vulnerability Database to address AI-driven challenges and incorporate more automation.
– The NVD currently ingests CVE records automatically within about an hour, with analysts adding details like severity scores, but NIST says traditional manual methods are becoming inadequate.
– The RFI highlights AI as both an opportunity for modernization and a risk due to AI-assisted vulnerability discovery and exploitation, aiming for a “continuous, contextual, and automated” system.
– The RFI includes 30 questions on integrating AI tools and automation workflows, with stakeholder input due by October 13.
– Tyler Reguly of Fortra notes AI can help find obscure vulnerabilities in source code, but warns against trusting AI for remediation in critical or production systems, emphasizing the need for human oversight.
The U.S. National Institute of Standards and Technology (NIST) has launched an initiative to overhaul its National Vulnerability Database (NVD), aiming to adapt the system for a cybersecurity environment where artificial intelligence plays an increasingly central role.
A request for information (RFI) published in the Federal Register on August 12 invites stakeholders to weigh in on the opportunities, challenges, and priorities for updating the NVD. NIST framed the modernization effort as a response to a landscape “increasingly shaped by AI and machine-consumable security data,” and is seeking “forward-looking perspectives, practical recommendations and innovative models” to enhance the database’s scalability, automation, interoperability, transparency, and utility.
Currently, the NVD ingests common vulnerabilities and exposures (CVE) records automatically within roughly an hour. Analysts then enrich those records with additional context, such as severity scores and affected product versions, before publishing them on the NVD website and through automated tools.
NIST acknowledged that the existing model, which relies on “periodic scanning, static prioritization, and manual remediation,” is no longer sufficient. The RFI points to a confluence of factors driving the change: AI-enabled security tools, accelerated technology development cycles, a rising volume of vulnerabilities, and growing demand for automation and near-real-time data.
The agency views AI as a potential catalyst for modernizing vulnerability management, but it also recognizes the risks, including the use of AI for vulnerability discovery and exploitation by malicious actors. NIST is asking for community input on how to build a system that is “continuous, contextual, and automated,” and that can respond effectively to both emerging threats and organizational priorities.
The RFI contains 30 questions, covering topics such as what the NVD should change and how it should integrate AI tools and automated workflows.
Tyler Reguly, associate director of security R&D at Fortra, sees clear benefits for AI in vulnerability discovery. He noted that AI can be especially useful when analyzing source code, as it can identify “all sorts of obscure vulnerabilities” that human researchers might miss.
But Reguly cautioned against placing too much trust in AI for remediation, particularly in critical or production environments. “I would not trust the remediation of vulnerabilities in critical systems to AI just yet,” he said, emphasizing that “human-in-the-loop is still so critical.” He added that AI-driven remediation may be acceptable in test environments and labs, but “in production systems, not yet.”
Interested stakeholders have until October 13 to submit their responses.
(Source: Infosecurity Magazine)