脆弱性(计算)
漏洞管理
脆弱性评估
计算机科学
软件
软件安全保证
计算机安全
保密
数据挖掘
信息安全
操作系统
心理学
保安服务
心理弹性
心理治疗师
作者
Xiaobing Sun,Zhenlei Ye,Lili Bo,Xiaoxue Wu,Weiqin Ying,Tao Zhang,Bin Li
标识
DOI:10.1016/j.jss.2023.111790
摘要
Software vulnerabilities take threats to software security. When faced with multiple software vulnerabilities, the most urgent ones need to be fixed first. Therefore, it is critical to assess the severity of vulnerabilities in advance. However, increasing number of vulnerability descriptions do not use templates, which reduces the performance of the existing software vulnerability assessment approaches. In this paper, we propose an automated vulnerability assessment approach that using vulnerability elements for predicting the severity of six vulnerability metrics (i.e., Access Vector, Access Complexity, Authentication, Confidentiality Impact, Integrity Impact and Availability Impact). First, we use BERT-MRC to extract vulnerability elements from vulnerability descriptions. Second, we assess six metrics using vulnerability elements instead of full descriptions. We conducted experiments on our manually labeled dataset. The experimental results show that our approach has an improvement of 12.03%, 14.37%, and 38.65% on Accuracy over three baselines.
科研通智能强力驱动
Strongly Powered by AbleSci AI