If approval is given, I'm sure the CPE Community would love to add this mapping to the list, and hopefully would be able to help build on the mapping for your own benefit.
>-----Original Message-----
>From: Steve Meulmeester [mailto:
[hidden email]]
>Sent: Monday, April 13, 2009 10:33 AM
>To: cpe-discussion-list CPE Community Forum
>Subject: Re: [CPE-DISCUSSION-LIST] API -> CPE map
>
>Andrew,
>At CSE we have just completed an excercise of extracting the CPE data
>into a tree structure and mapping Assurent, Symantec and Idefense data
>to this tree. We created normalized models that support each of the
>vendors (including the CPE) and processed the supplied XML populating
>the structures. We then attempted to map the normalized data from the
>Vendors across a normalized model of the CPE using an Oracle
>implementation of the Levenshtein text matching algorithm. We had
>varying levels of success with the mapping and we created a web user
>interface that displayed the mapping and permits the user community to
>change the mapping. The Vendor supplied vulnerabilities are then
>dynamically mapped to the CPE depending on the mapping (ie if the
>mapping changes so do the vulnerabilities).
>
>Our premise is that the Vendors supply a consistent set of Asset
>Information in the XML and that newly created Vendors, Assets or Asset
>Versions occur infrequently. The mapping that you are describing would
>have been extremely beneficial to our recent activities and in the short
>run is probably the only practical alternative to creating a singular
>view of Assets. Subject to approval from our Project Manager/Authority
>we would be able to contribute our attempt at the mapping back to the
>community. Further, a demo or at least screen shots of the functioning
>system might be helpful to illustrate what we have produced.
>
>Thanks,
>Steve Meulmeester
>TVAS Developer
>613-949-6297
>
>On Mon, Apr 13, 2009 at 9:32 AM, Buttner, Drew <
[hidden email]>
>wrote:
>
>
> After talking with a vendor recently, an idea was presented that I
>have heard in the past. I think the time might be right to make it
>happen. In short, the creation of a shared map between the return of
>certain API calls and the CPE Name that the value would map to.
>
> This would help anyone who is trying to move between the
>information that a system might return and the official CPE Name.
>Without this information, a manual map would have to be performed.
>Hopefully this would help make it easier for vendors to add CPE to their
>tools.
>
> The plan for now would be to just create a file and post it on the
>CPE site. The format for this file will evolve over time as we learn
>more about it. Right now I am thinking about something quick and dirty.
>Any thoughts as to how to initially set this up? For some CPE Names it
>might be a collection of CPE Name?
>
> Thoughts about this idea? Would it be helpful?
>
> Thanks
> Drew
>
> ---------
>
> Andrew Buttner
> The MITRE Corporation
>
[hidden email]
> 781-271-3515
>
>