OTHMAN, Refat T A, Bruno ROSSI a Barbara RUSSO. Cybersecurity Defenses: Exploration of CVE Types through Attack Descriptions. In 50th Euromicro Conference Series on Software Engineering and Advanced Applications (SEAA). IEEE, 2024.
Další formáty:   BibTeX LaTeX RIS
Základní údaje
Originální název Cybersecurity Defenses: Exploration of CVE Types through Attack Descriptions
Autoři OTHMAN, Refat T A, Bruno ROSSI a Barbara RUSSO.
Vydání 50th Euromicro Conference Series on Software Engineering and Advanced Applications (SEAA), 2024.
Nakladatel IEEE
Další údaje
Originální jazyk angličtina
Typ výsledku Stať ve sborníku
Obor 10200 1.2 Computer and information sciences
Utajení není předmětem státního či obchodního tajemství
Klíčová slova anglicky MITRE; CAPEC; CVE; Transformer models; Pretrained language models
Příznaky Mezinárodní význam, Recenzováno
Změnil Změnil: Bruno Rossi, PhD, učo 232464. Změněno: 7. 8. 2024 10:16.
Anotace
Vulnerabilities in software security can remain undiscovered even after being exploited. Linking attacks to vulnerabilities helps experts identify and respond promptly to the incident. This paper introduces VULDAT, a classification tool using a sentence transformer MPNET to identify system vulnerabilities from attack descriptions. Our model was applied to 100 attack techniques from the ATT&CK repository and 685 issues from the CVE repository. Then, we compare the performance of VULDAT against the other eight state-of-the-art classifiers based on sentence transformers. Our findings indicate that our model achieves the best performance with F1 score of 0.85, Precision of 0.86, and Recall of 0.83. Furthermore, we found 56% of CVE reports vulnerabilities associated with an attack were identified by VULDAT, and 61% of identified vulnerabilities were in the CVE repository.
VytisknoutZobrazeno: 6. 10. 2024 14:43