Common Product Enumeration;
Common Vulnerability;
and Exposures;
Natural Language Processing;
Software Product Name Extraction;
Software Vulnerability;
D O I:
10.1109/STC55697.2022.00024
中图分类号:
TP31 [计算机软件];
学科分类号:
081202 ;
0835 ;
摘要:
Software vulnerabilities are closely monitored by the security community to timely address the security and privacy issues in software systems. Before a vulnerability is published by vulnerability management systems, it needs to be characterized to highlight its unique attributes, including affected software products and versions, to help security professionals prioritize their patches. Associating product names and versions with disclosed vulnerabilities may require a labor-intensive process that may delay their publication and fix, and thereby give attackers more time to exploit them. This work proposes a machine learning method to extract software product names and versions from unstructured CVE descriptions automatically. It uses Word2Vec and Char2Vec models to create context-aware features from CVE descriptions and uses these features to train a Named Entity Recognition (NER) model using bidirectional Long short-term memory (LSTM) networks. Based on the attributes of the product names and versions in previously published CVE descriptions, we created a set of Expert System (ES) rules to refine the predictions of the NER model and improve the performance of the developed method. Experiment results on real-life CVE examples indicate that using the trained NER model and the set of ES rules, software names and versions in unstructured CVE descriptions could be identified with FMeasure values above 0.95.
机构:
Swansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, WalesSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Fonferko-Shadrach, Beata
Lacey, Arron S.
论文数: 0引用数: 0
h-index: 0
机构:
Swansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Swansea Univ, Sch Med, Hlth Data Res UK, Data Sci Bldg, Swansea, W Glam, WalesSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Lacey, Arron S.
Roberts, Angus
论文数: 0引用数: 0
h-index: 0
机构:
Kings Coll London, Inst Psychiat Psychol & Neurosci, London, EnglandSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Roberts, Angus
Akbari, Ashley
论文数: 0引用数: 0
h-index: 0
机构:
Swansea Univ, Sch Med, Hlth Data Res UK, Data Sci Bldg, Swansea, W Glam, WalesSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Akbari, Ashley
Thompson, Simon
论文数: 0引用数: 0
h-index: 0
机构:
Swansea Univ, Sch Med, Hlth Data Res UK, Data Sci Bldg, Swansea, W Glam, WalesSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Thompson, Simon
Ford, David V.
论文数: 0引用数: 0
h-index: 0
机构:
Swansea Univ, Sch Med, Hlth Data Res UK, Data Sci Bldg, Swansea, W Glam, WalesSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Ford, David V.
Lyons, Ronan A.
论文数: 0引用数: 0
h-index: 0
机构:
Swansea Univ, Sch Med, Hlth Data Res UK, Data Sci Bldg, Swansea, W Glam, WalesSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Lyons, Ronan A.
Rees, Mark I.
论文数: 0引用数: 0
h-index: 0
机构:
Swansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Univ Sydney, Fac Med & Hlth, Sydney, NSW, AustraliaSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales
Rees, Mark I.
Pickrell, William Owen
论文数: 0引用数: 0
h-index: 0
机构:
Swansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, WalesSwansea Univ, Sch Med, Inst Life Sci, Neurol & Mol Neurosci Grp, Swansea, W Glam, Wales