返回
Automatic software vulnerability assessment by extracting vulnerability elements
DOI:10.1016/j.jss.2023.111790.png)
摘要
En 中文
Software vulnerabilities take threats to software security. When faced with multiple software vulnerabilities, the most urgent ones need to be fixed first. Therefore, it is critical to assess the severity of vulnerabilities in advance. However, increasing number of vulnerability descriptions do not use templates, which reduces the performance of the existing software vulnerability assessment approaches. In this paper, we propose an automated vulnerability assessment approach that using vulnerability elements for predicting the severity of six vulnerability metrics (i.e., Access Vector, Access Complexity, Authentication, Confidentiality Impact, Integrity Impact and Availability Impact). First, we use BERT-MRC to extract vulnerability elements from vulnerability descriptions. Second, we assess six metrics using vulnerability elements instead of full descriptions. We conducted experiments on our manually labeled dataset. The experimental results show that our approach has an improvement of 12.03%, 14.37%, and 38.65% on Accuracy over three baselines.& COPY; 2023 Elsevier Inc. All rights reserved.
Keyword:
Vulnerability assessment
Deep learning
Multi-class classification
Mining software repositories
期刊
IF:
4.1
论文数:
5.4K
被引数:
8.4K
机构
引用论文
Habitat Characteristics That Influence the Occurrence of Wood Turtles at the Southern Limits of Their Range in the Central Appalachians影响中央阿巴拉契亚山脉南缘木龟分布的栖息地特征

