Severity prediction of software vulnerabilities using convolutional neural networks

被引:0
|
作者
Saklani, Santosh [1 ]
Kalia, Anshul [1 ]
机构
[1] Himachal Pradesh Univ, Dept Comp Sci, Shimla, India
关键词
Machine learning; Natural language processing; Convolutional neural network (CNN); Software vulnerability; Common vulnerability scoring system (CVSS);
D O I
10.1108/ICS-10-2024-0265
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
PurposeThe continuous influx of software vulnerabilities poses a significant challenge to organizations, necessitating effective resource allocation for threat mitigation. A key factor in this process is assessing the severity of vulnerabilities to prioritize which issues require immediate attention. This paper aims to automate the prediction of common vulnerability scoring system (CVSS) metrics from textual descriptions of vulnerabilities, reducing the reliance on manual expert analysis.Design/methodology/approachThis study applies machine learning and natural language processing techniques, particularly convolutional neural networks (CNNs), to predict CVSS base metrics such as attack vectors, attack complexity and required privileges. The CNN models are trained on vulnerability descriptions and evaluated for their accuracy in predicting these metrics, which are then used to compute overall severity base scores.FindingsThe CNN models demonstrated high accuracy in predicting CVSS base metrics from textual descriptions. The predicted severity base scores closely align with those provided by human experts, showing the model's potential to streamline the vulnerability assessment process.Practical implicationsAutomating CVSS metric prediction could significantly reduce the time and effort required for vulnerability severity assessment. This would enable security teams to quickly identify and prioritize critical vulnerabilities, improving response times in cybersecurity management.Originality/valueThis research provides an innovative approach to vulnerability management by automating CVSS metric prediction, reducing the need for manual expert analysis and therefore accelerating security assessments.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Software Defect Prediction using Convolutional Neural Network
    Wongpheng, Kittisak
    Visutsak, Porawat
    35TH INTERNATIONAL TECHNICAL CONFERENCE ON CIRCUITS/SYSTEMS, COMPUTERS AND COMMUNICATIONS (ITC-CSCC 2020), 2020, : 240 - 243
  • [2] Severity Prediction of Software Vulnerabilities based on their Text Description
    Babalau, Ion
    Corlatescu, Dragos
    Grigorescu, Octavian
    Sandescu, Cristian
    Dascalu, Mihai
    2021 23RD INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC 2021), 2021, : 171 - 177
  • [3] Detecting Software Code Vulnerabilities Using 2D Convolutional Neural Networks with Program Slicing Feature Maps
    Watson, Anne
    Ufuktepe, Ekincan
    Palaniappan, Kannappan
    2022 IEEE APPLIED IMAGERY PATTERN RECOGNITION WORKSHOP, AIPR, 2022,
  • [4] Software Defect Prediction Using Neural Networks
    Jindal, Rajni
    Malhotra, Ruchika
    Jain, Abha
    2014 3RD INTERNATIONAL CONFERENCE ON RELIABILITY, INFOCOM TECHNOLOGIES AND OPTIMIZATION (ICRITO) (TRENDS AND FUTURE DIRECTIONS), 2014,
  • [5] Rainfall Prediction using Spatial Convolutional Neural Networks and Recurrent Neural Networks
    Lestari, Nadia Dwi Puji
    Djamal, Esmeralda Contessa
    2022 International Conference on Data Science and Its Applications, ICoDSA 2022, 2022, : 12 - 17
  • [6] Rainfall Prediction using Spatial Convolutional Neural Networks and Recurrent Neural Networks
    Lestari, Nadia Dwi Puji
    Djamal, Esmeralda Contessa
    2022 INTERNATIONAL CONFERENCE ON DATA SCIENCE AND ITS APPLICATIONS (ICODSA), 2022, : 12 - 17
  • [7] Time Series Prediction using Convolutional Neural Networks
    Asesh, Aishwarya
    Dugar, Meenal
    2023 IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLIED NETWORK TECHNOLOGIES, ICMLANT, 2023, : 29 - 34
  • [8] Prediction of Diabetic Retinopathy using Convolutional Neural Networks
    Alsuwat, Manal
    Alalawi, Hana
    Alhazmi, Shema
    Al-Shareef, Sarah
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (07) : 843 - 852
  • [9] Using Local Convolutional Neural Networks for Genomic Prediction
    Pook, Torsten
    Freudenthal, Jan
    Korte, Arthur
    Simianer, Henner
    FRONTIERS IN GENETICS, 2020, 11
  • [10] Word Difficulty Prediction Using Convolutional Neural Networks
    Basu, Arpan
    Garain, Avishek
    Naskar, Sudip Kumar
    PROCEEDINGS OF THE 2019 IEEE REGION 10 CONFERENCE (TENCON 2019): TECHNOLOGY, KNOWLEDGE, AND SOCIETY, 2019, : 1109 - 1112