1
Return

Event-centric semantic alignment of vulnerabilities with adversarial attack techniques

delete2026-08-13
delete0
PRE
AI
S
Swapnil Pandey
T
Tanmay Joshi
R
Rajesh Kumar *
DOI:10.1007/s10489-026-07410-ydelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Many cyber-threat knowledge databases possess complementary information. For example, the popular Common Vulnerabilities and Exposures (CVE) repository catalogs known software weaknesses. Meanwhile the MITRE ATT&CK framework documents the tactics and techniques that adversaries use to exploit these vulnerabilities. Despite a natural correspondence, linking vulnerability descriptions with attacker techniques remains largely manual. This is due to differences in abstraction levels and linguistic representation. Existing automated approaches have made progress by relying on multi-stage pipelines or surface textual similarity. However, they often fail to capture the underlying attack events. Moreover, these approaches limit generalization for newly disclosed vulnerabilities. This paper introduces SemanticLink, an event-centric semantic representation framework that enables automated alignment between CVE vulnerability descriptions and ATT&CK techniques through a single integrated learning pipeline. The approach uses semantic role labeling to extract structured attack events, capturing actions, targets, and exploitation context. These event representations are combined with a Siamese transformer architecture and cross-sentence attention to enable semantically grounded similarity learning. A contrastive learning strategy further improves discrimination among closely related attack techniques. We evaluate our approach on a dataset of 6,602 curated CVE-ATT&CK mappings. SemanticLink achieves a mean accuracy of 93.43% and an F1-score of 87.36%. These results outperform existing transformer-based mapping approaches. Beyond performance, the event-centric representation supports attention-based transparency through learned attention weights over semantically tagged spans to support practical applications such as vulnerability triage, threat modeling, and threat intelligence enrichment. Finally, to support reproducibility and community adoption, we publicly release the dataset and implementation.
Keywords:
Threat databases
Deep learning model
Siamese model
ATT& CK
CWE

Journal

Applied Intelligence cover
Applied Intelligence
IF:
3.5
Papers:
7.5K
Citations:
1.7W

Organization

Cited Papers

Cited Papers

Citing Papers

Citing Papers