Forecasting Cybersecurity Data: Making Sense of the Senseless @FIRSTdotorg
Forecasting Cybersecurity Data: Making Sense of the Senseless  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 13 hours ago
Vijay Sarvepalli (US)

Vijay Sarvepalli is a Principal Engineer at the CERT Coordination Center, part of the Software Engineering Institute at Carnegie Mellon University. He supports sponsors in areas including enterprise architecture, cybersecurity, and situational awareness, with a focus on vulnerability analysis for the Threat Analysis Directorate. His current work includes systemic vulnerability research, scalable vulnerability coordination, and threat modeling. Vijay has over 20 years of experience across electrical engineering, software engineering, and enterprise architecture. He holds an M.S. in Electrical and Computer Engineering from the University of Utah and certifications including TOGAF, ITIL, and GIAC Gold. His research has been published in IEEE, Applied Physics Journal, International Journal of Engineering, IEEE publications, and the ANTS Swarm Intelligence Conference.
--
Planning resource management in cybersecurity is difficult and is always affected by the trends. How many vulnerabilities do we expect? How much malware? How many security incidents? Unfortunately, these trends are often affected by multiple causes that are not always related. For example, a new threat actor, a new malware library, a new class of vulnerability, or a new method of finding vulnerabilities. They may be interrelated, they may be unrelated, and they may be unknown, but at the core, they influence how many vulnerabilities, malware, incidents, and other cybersecurity events occur.As an outgrowth of analyzing COVID-19 trends and causes, we developed a new method for modeling multicausal data, which can have disparate underlying causes for the changes in trends. This method has been expanded to prediction, where we predict the point at which the trend in data changes, allowing us to forecast the number of events in the future.
Forecasting Cybersecurity Data: Making Sense of the SenselessHow EPSS Is Wrong and Useful at the Same TimeWhy is Finnish Healthcare Doing So Well Against Ransomware?The Funny Story of Active Directory BackdooringPivoting To Resilience: Disruptive Incidents And How We Prepare For ThemLessons From NPMs Dark Side: Preventing the Next Shai-HuludThe CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code DietAll Ransomware Economic Models are Wrong, But This One is UsefulCISA-ENISA Joint MessagingPanel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...Bringing Actionable Data to Internet DefendersUnlocking Insights: The Role of TI in Modern DFIR Operations
FIRST |

Forecasting Cybersecurity Data: Making Sense of the Senseless

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER