A Compact Vulnerability Knowledge Graph for Risk Assessment

被引:2
|
作者
Yin, Jiao [1 ]
Hong, Wei [2 ]
Wang, Hua [1 ]
Cao, Jinli [3 ]
Miao, Yuan [1 ]
Zhang, Yanchun [1 ]
机构
[1] Victoria Univ, Inst Sustainable Ind & Liveable Cities, Melbourne, Vic, Australia
[2] Chongqing Univ Arts & Sci, Sch Artificial Intelligence, Chongqing, Peoples R China
[3] La Trobe Univ, Dept Comp Sci & Informat Technol, Melbourne, Vic, Australia
关键词
Knowledge graph; vulnerability risk assessment; vulnerability co-exploitation; link prediction;
D O I
10.1145/3671005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software vulnerabilities, also known as flaws, bugs or weaknesses, are common in modern informationsystems, putting critical data of organizations and individuals at cyber risk. Due to the scarcity of resources,initial risk assessment is becoming a necessary step to prioritize vulnerabilities and make better decisions onremediation, mitigation, and patching. Datasets containing historical vulnerability information are crucialdigital assets to enable AI-based risk assessments. However, existing datasets focus on collecting informationon individual vulnerabilities while simply storing them in relational databases, disregarding their structuralconnections. This article constructs a compact vulnerability knowledge graph, VulKG, containing over 276 Knodes and 1 M relationships to represent the connections between vulnerabilities, exploits, affected products,vendors, referred domain names, and more. We provide a detailed analysis of VulKG modeling and construction,demonstrating VulKG-based query and reasoning, and providing a use case of applying VulKG to a vulnerabilityrisk assessment task, i.e., co-exploitation behavior discovery. Experimental results demonstrate the value ofgraph connections in vulnerability risk assessment tasks. VulKG offers exciting opportunities for more noveland significant research in areas related to vulnerability risk assessment.
引用
收藏
页数:1
相关论文
共 50 条
  • [21] Vulnerability and risk: comparing assessment approaches
    Sarah Wolf
    Natural Hazards, 2012, 61 : 1099 - 1113
  • [22] Vulnerability and risk: comparing assessment approaches
    Wolf, Sarah
    NATURAL HAZARDS, 2012, 61 (03) : 1099 - 1113
  • [23] Conducting a Climate Risk Vulnerability Assessment
    White, Julie D.
    Edwards, Victor H.
    CHEMICAL ENGINEERING PROGRESS, 2023, 119 (01) : 44 - 51
  • [24] Risk and Vulnerability Assessment for International Contractors
    Maddah, Rouzbeh
    Tripathi, Kamalendra Kumar
    Jha, Kumar Neeraj
    JOURNAL OF LEGAL AFFAIRS AND DISPUTE RESOLUTION IN ENGINEERING AND CONSTRUCTION, 2025, 17 (02)
  • [25] Ontology-based Vulnerability Knowledge Graph of Network Routing Mechanism
    Zhang, Yu
    Zhuang, Yi
    2024 5TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND APPLICATION, ICCEA 2024, 2024, : 51 - 55
  • [26] NETWORK ATTACK PATH PREDICTION BASED ON VULNERABILITY DATA AND KNOWLEDGE GRAPH
    Wang, Yifan
    Sun, Zhi
    Han, Ye
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2021, 17 (05): : 1717 - 1730
  • [27] Assessment of Windows system security using vulnerability relationship graph
    Zhang, YZ
    Fang, BX
    Chi, Y
    Yun, XC
    COMPUTATIONAL INTELLIGENCE AND SECURITY, PT 2, PROCEEDINGS, 2005, 3802 : 415 - 420
  • [28] Vulnerability Assessment of Power Grid Using Graph Topological Indices
    Kim, Charles J.
    Obah, Obinna B.
    INTERNATIONAL JOURNAL OF EMERGING ELECTRIC POWER SYSTEMS, 2007, 8 (06):
  • [29] A Multi-faceted Vulnerability Searching Website Powered by Aspect-level Vulnerability Knowledge Graph
    Sun, Jiamou
    Xing, Zhenchang
    Lu, Qinghua
    Xu, Xiwei
    Zhu, Liming
    2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS, ICSE-COMPANION, 2023, : 60 - 63
  • [30] Development of the TOXIN Knowledge Graph for assisting animal-free risk assessment of cosmetic ingredients
    Sepehri, S.
    Maushagen, J.
    Vrijens, G.
    Debruyne, C.
    Rodrigues, R. Marcelino
    Sanctorum, A.
    De Troyer, O.
    Vanhaecke, T.
    TOXICOLOGY LETTERS, 2023, 384 : S103 - S103