Automated event extraction of CVE descriptions

被引:4
|
作者
Wei, Ying [1 ]
Bo, Lili [1 ,2 ]
Sun, Xiaobing [1 ]
Li, Bin [1 ]
Zhang, Tao [3 ]
Tao, Chuanqi [4 ]
机构
[1] Yangzhou Univ, Sch Informat Engn, Yangzhou, Peoples R China
[2] Nanjing Univ, State Key Lab Novel Software Technol, Nanjing, Peoples R China
[3] Macau Univ Sci & Technol, Sch Comp Sci & Engn, Macao Special Adm Reg China, Zhuhai, Peoples R China
[4] Nanjing Univ Aeronaut & Astronaut, Coll Comp Sci & Technol, Coll Artificial Intelligence, Nanjing, Peoples R China
基金
中国国家自然科学基金;
关键词
Vulnerability events; Event extraction; Vulnerability analysis; JOINT ENTITY; CLASSIFICATION; AGREEMENT;
D O I
10.1016/j.infsof.2023.107178
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Context: The dramatically increasing number of vulnerabilities makes manual vulnerability analysis increasingly more difficult. Automatic extraction of vulnerability information can help improve vulnerability analysis. However, the existing vulnerability information extraction methods do not extract from the perspective of events, and the existing event extraction methods do not consider the unique sentence structure characteristics of vulnerability descriptions, which makes it difficult to extract vulnerability information effectively.Objective: To extract vulnerability information, we treat each vulnerability as an event, and propose an approach, VE-Extractor, to automatically perform vulnerability event extraction from textual descriptions in vulnerability reports for vulnerability analysis, including extraction of vulnerability event trigger (cause) and event arguments (e.g., consequence, operation).Method: First, we propose a new labeling method BIOFR (Begin, Inside, Outside, Front, Rear) to construct an event-perspective vulnerability data benchmark. Then, we design a question template based on event trigger, to automatically extract vulnerability event arguments through the BERT Q&A model.Results: Experiments show the effectiveness of VE-Extractor for automatically extracting events from vulnerability description, with significant performance improvement over state-of-the-art techniques, e.g., F1-score is increased by 45.12% and 21.02% in vulnerability consequence and operation extraction, respectively.Conclusion: The proposed VE-Extractor achieves a higher precision and accuracy than the state-of-the-art methods. Experiments results show that our approach is effective in extracting vulnerability event information and can be used to assist vulnerability analysis, such as vulnerability classification.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] EXTRACTION OF MOVING OBJECT DESCRIPTIONS VIA DIFFERENCING
    YALAMANCHILI, S
    MARTIN, WN
    AGGARWAL, JK
    [J]. COMPUTER GRAPHICS AND IMAGE PROCESSING, 1982, 18 (02): : 188 - 201
  • [42] Manner and path in motion event descriptions in English and Korean
    Oh, KJ
    [J]. BUCLD 27: ANNUAL BOSTON UNIVERSITY CONFERENCE ON LANGUAGE DEVELOPMENT, VOLS 1 AND 2, PROCEEDINGS, 2003, : 580 - 590
  • [43] Automated Trace Signals Selection using the RTL Descriptions
    Ko, Ho Fai
    Nicolici, Nicola
    [J]. INTERNATIONAL TEST CONFERENCE 2010, 2010,
  • [44] Generating logic descriptions for the automated interpretation of topographic maps
    Lanza, A
    Malerba, D
    Lisi, FA
    Appice, A
    Ceci, M
    [J]. GRAPHICS RECOGNITION: ALGORITHMS AND APPLICATIONS, 2002, 2390 : 200 - 210
  • [45] Robocrystallographer: automated crystal structure text descriptions and analysis
    Ganose, Alex M.
    Jain, Anubhav
    [J]. MRS COMMUNICATIONS, 2019, 9 (03) : 874 - 881
  • [46] Automated Circuit Elaboration from Incomplete Architectural Descriptions
    Becker, Andrew
    Novo, David
    Ienne, Paolo
    [J]. 2013 ASILOMAR CONFERENCE ON SIGNALS, SYSTEMS AND COMPUTERS, 2013, : 391 - 395
  • [47] Automated Web Service Composition Using Semantic Descriptions
    Bellur, Umesh
    Mande, Tanmay
    [J]. 2009 IEEE ASIA-PACIFIC SERVICES COMPUTING CONFERENCE (APSCC 2009), 2009, : 335 - 342
  • [48] Robocrystallographer: automated crystal structure text descriptions and analysis
    Alex M. Ganose
    Anubhav Jain
    [J]. MRS Communications, 2019, 9 : 874 - 881
  • [49] Evaluation of Automated Image Descriptions for Visually Impaired Students
    Hoppe, Anett
    Morris, David
    Ewerth, Ralph
    [J]. ARTIFICIAL INTELLIGENCE IN EDUCATION (AIED 2021), PT II, 2021, 12749 : 196 - 201
  • [50] Bio-molecular event extraction by integrating multiple event-extraction systems
    Majumder, Amit
    Ekbal, Asif
    Naskar, Sudip Kumar
    [J]. SADHANA-ACADEMY PROCEEDINGS IN ENGINEERING SCIENCES, 2019, 44 (01):