Using Common Platform Enumeration (CPE)

Prev Next

Common Platform Enumeration (CPE) is a feature that matches applications in the Application Control inventory with applications registered on the CPE official dictionary or custom CPE dictionary, using different matching methods.

The CPE official dictionary is hosted and maintained by the National Institute of Standards and Technology (NIST). It can be downloaded from https://nvd.nist.gov/products/cpe.

Note

The CPE feature needs Application Control or Integrity Monitor licenses to work.

If the Solidcore extension is upgraded from a previous version that already has inventory populated, the matching runs between the populated inventory and the CPE dictionary. We recommend that you fetch inventory applications again to improve the matching between the inventory and the CPE dictionary.

Specifying matching methods for applications

Different matching methods are specified for inventory applications based on the type of matching.

  • Canonical — Applications that match with the NIST official dictionary.

  • Custom — Applications that match with the custom created dictionary.

  • Generated — Applications that don't match with any of the imported dictionaries. The Solidcore extension creates a CPE name for them.

Dictionary Types

You can import different types of dictionaries to the CPE page.

  • Official dictionary — Applications that are registered on the NIST CPE page.

  • Custom dictionary — Applications that don't match the CPE official page. It is exported from CPE names generated on the ePO - On-prem Common Platform Enumeration page.

  • Managed Custom dictionary — Applications that have a CPE-generated name, that is marked as Managed Custom. They are added to a dictionary type that can be edited from the ePO - On-prem CPE dictionaries page.