Predicting the Severity and Exploitability of Vulnerability Reports using Convolutional Neural Nets

被引:0
|
作者
Okutan, Ahmet [1 ]
Mirakhorli, Mehdi [1 ]
机构
[1] Rochester Inst Technol, Rochester, NY 14623 USA
关键词
Software Vulnerability; CVE; CVSS Scoring; Exploitability;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Common Vulnerability and Exposure (CVE) reports published by Vulnerability Management Systems (VMSs) are used to evaluate the severity and exploitability of software vulnerabilities. Public vulnerability databases such as NVD uses the Common Vulnerability Scoring System (CVSS) to assign various scores to CVEs to evaluate their base severity, impact, and exploitability. Previous studies have shown that vulnerability databases rely on a manual, labor-intensive and error-prone process which may lead to inconsistencies in the CVE data and delays in the releasing of new CVEs. Furthermore, it was shown that CVSS scoring is based on complex calculations and may not be accurate enough in assessing the potential severity and exploitability of vulnerabilities in real life. This work uses Convolutional Neural Networks (CNN) to train text classification models to automate the prediction of the severity and exploitability of CVEs, and proposes a new exploitability scoring method by creating a Product Hygiene Index based on the Common Product Enumeration (CPE) catalog. Using CVE descriptions published by the NVD and the exploits identified by exploit databases, it trains CNN models to predict the base severity and exploitability of CVEs. Preliminary experiment results and the conducted case study indicate that the severity of CVEs can be predicted automatically with high confidences, and the proposed exploitability scoring method achieves better results compared to the exploitability scoring provided by the NVD.
引用
收藏
页码:1 / 8
页数:8
相关论文
共 50 条
  • [21] Predicting Missing Information of Vulnerability Reports
    Guo, Hao
    Xing, Zhenchang
    Li, Xiaohong
    WWW'20: COMPANION PROCEEDINGS OF THE WEB CONFERENCE 2020, 2020, : 81 - 82
  • [22] Automated Pain Severity Detection Using Convolutional Neural Network
    Semwal, Ashish
    Londhe, Narendra D.
    PROCEEDINGS OF THE 2018 INTERNATIONAL CONFERENCE ON COMPUTATIONAL TECHNIQUES, ELECTRONICS AND MECHANICAL SYSTEMS (CTEMS), 2018, : 66 - 70
  • [23] Optical Flow Estimation with Convolutional Neural Nets
    Shah, Syed Tafseer Haider
    Xiang Xuezhi
    Ahmed, Waqas
    PATTERN RECOGNITION AND IMAGE ANALYSIS, 2021, 31 (04) : 656 - 670
  • [24] Knowledge transfer in deep convolutional neural nets
    Gutstein, Steven
    Fuentes, Olac
    Freudenthal, Eric
    INTERNATIONAL JOURNAL ON ARTIFICIAL INTELLIGENCE TOOLS, 2008, 17 (03) : 555 - 567
  • [25] Entangled q-convolutional neural nets
    Anagiannis, Vassilis
    Cheng, Miranda C. N.
    MACHINE LEARNING-SCIENCE AND TECHNOLOGY, 2021, 2 (04):
  • [26] Optical Flow Estimation with Convolutional Neural Nets
    Xiang Syed Tafseer Haider Shah
    Waqas Xuezhi
    Pattern Recognition and Image Analysis, 2021, 31 : 656 - 670
  • [27] Targeted Wavelet Based Image Aesthetics Classification using Convolutional Neural Nets
    Venkataswamy, Prashanth
    Ahmad, M. Omair
    Swamy, M. N. S.
    2018 IEEE CANADIAN CONFERENCE ON ELECTRICAL & COMPUTER ENGINEERING (CCECE), 2018,
  • [28] Texture Mapping of Flags onto Polandball Characters using Convolutional Neural Nets
    Arvidsson, Simon
    Gabrielsson, Patrick
    Johansson, Ulf
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [29] Inferring depth contours from sidescan sonar using convolutional neural nets
    Xie, Yiping
    Bore, Nils
    Folkesson, John
    IET RADAR SONAR AND NAVIGATION, 2020, 14 (02): : 328 - 334
  • [30] Predicting pedestrian crosswalk behavior using Convolutional Neural Networks
    Liang, Eric
    Stamp, Mark
    TRAFFIC INJURY PREVENTION, 2023, 24 (04) : 338 - 343