Severity prediction of software vulnerabilities using convolutional neural networks

被引:0
|
作者
Saklani, Santosh [1 ]
Kalia, Anshul [1 ]
机构
[1] Himachal Pradesh Univ, Dept Comp Sci, Shimla, India
关键词
Machine learning; Natural language processing; Convolutional neural network (CNN); Software vulnerability; Common vulnerability scoring system (CVSS);
D O I
10.1108/ICS-10-2024-0265
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
PurposeThe continuous influx of software vulnerabilities poses a significant challenge to organizations, necessitating effective resource allocation for threat mitigation. A key factor in this process is assessing the severity of vulnerabilities to prioritize which issues require immediate attention. This paper aims to automate the prediction of common vulnerability scoring system (CVSS) metrics from textual descriptions of vulnerabilities, reducing the reliance on manual expert analysis.Design/methodology/approachThis study applies machine learning and natural language processing techniques, particularly convolutional neural networks (CNNs), to predict CVSS base metrics such as attack vectors, attack complexity and required privileges. The CNN models are trained on vulnerability descriptions and evaluated for their accuracy in predicting these metrics, which are then used to compute overall severity base scores.FindingsThe CNN models demonstrated high accuracy in predicting CVSS base metrics from textual descriptions. The predicted severity base scores closely align with those provided by human experts, showing the model's potential to streamline the vulnerability assessment process.Practical implicationsAutomating CVSS metric prediction could significantly reduce the time and effort required for vulnerability severity assessment. This would enable security teams to quickly identify and prioritize critical vulnerabilities, improving response times in cybersecurity management.Originality/valueThis research provides an innovative approach to vulnerability management by automating CVSS metric prediction, reducing the need for manual expert analysis and therefore accelerating security assessments.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] Prediction of Froth Flotation Performance Using Convolutional Neural Networks
    Jahedsaravani, A.
    Massinaei, M.
    Zarie, M.
    MINING METALLURGY & EXPLORATION, 2023, 40 (03) : 923 - 937
  • [22] Prediction to Atrial Fibrillation Using Deep Convolutional Neural Networks
    Cho, Jungrae
    Kim, Yoonnyun
    Lee, Minho
    PREDICTIVE INTELLIGENCE IN MEDICINE, 2018, 11121 : 164 - 171
  • [23] Prediction of aerodynamic flow fields using convolutional neural networks
    Saakaar Bhatnagar
    Yaser Afshar
    Shaowu Pan
    Karthik Duraisamy
    Shailendra Kaushik
    Computational Mechanics, 2019, 64 : 525 - 545
  • [24] Prediction of Froth Flotation Performance Using Convolutional Neural Networks
    A. Jahedsaravani
    M. Massinaei
    M. Zarie
    Mining, Metallurgy & Exploration, 2023, 40 : 923 - 937
  • [25] Early Prediction of Sepsis Using Convolutional and Recurrent Neural Networks
    Devi, S. K. Chaya
    Reddy, Y. Varun
    Vasthav, K. Sai Sri
    Praneeth, G.
    ADVANCES IN SIGNAL PROCESSING AND COMMUNICATION ENGINEERING, ICASPACE 2021, 2022, 929 : 55 - 61
  • [26] Prediction of turbulent heat transfer using convolutional neural networks
    Kim, Junhyuk
    Lee, Changhoon
    JOURNAL OF FLUID MECHANICS, 2020, 882
  • [27] Prediction of aerodynamic flow fields using convolutional neural networks
    Bhatnagar, Saakaar
    Afshar, Yaser
    Pan, Shaowu
    Duraisamy, Karthik
    Kaushik, Shailendra
    COMPUTATIONAL MECHANICS, 2019, 64 (02) : 525 - 545
  • [28] Move Prediction Using Deep Convolutional Neural Networks in Hex
    Gao, Chao
    Hayward, Ryan
    Mueller, Martin
    IEEE TRANSACTIONS ON GAMES, 2018, 10 (04) : 336 - 343
  • [29] Prediction of Heart Disease Using Deep Convolutional Neural Networks
    Mehmood, Awais
    Iqbal, Munwar
    Mehmood, Zahid
    Irtaza, Aun
    Nawaz, Marriam
    Nazir, Tahira
    Masood, Momina
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2021, 46 (04) : 3409 - 3422
  • [30] Spontaneous Preterm Birth Prediction Using Convolutional Neural Networks
    Wlodarczyk, Tomasz
    Plotka, Szymon
    Rokita, Przemyslaw
    Sochacki-Wojcicka, Nicole
    Wojcicki, Jakub
    Lipa, Michal
    Trzcinski, Tomasz
    MEDICAL ULTRASOUND, AND PRETERM, PERINATAL AND PAEDIATRIC IMAGE ANALYSIS, ASMUS 2020, PIPPI 2020, 2020, 12437 : 274 - 283