Return
Model-Based Cybersecurity: Automating Common Vulnerabilities Reporting
DOI:10.1002/sys.70064.png)
Abstract
En 中文
The Common Vulnerabilities and Exposures (CVE) Program's mission is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. A cybersecurity practitioner who suspects a software, hardware, or service vulnerability, can initiate a CVE-ID Requesting process, as defined by MITRE. This process is cumbersome, as it is entirely textual and evolvable, making it prone to incomplete description and misinterpretations. To automate and streamline the process, we developed a model of this process using Object-Process Methodology (OPM ISO 19450:2024). The model features computational capabilities, enabling practitioners to feed a textual description of the potential vulnerability they wish to report for CVE-ID Requesting. In response, the system provides all matching CVE Numbering Authority (CNA) instances in a descending relevance order. A survey that evaluates the effectiveness of this model-based approach has shown that it formally explicates the CVE-ID Requesting process and automates it. This greatly alleviates the task of determining what CNA is best suitable for examining the potential CVE for which a number is sought. Beyond streamlining and automating the process, this work demonstrates the benefits of adopting an approach to cybersecurity that standardizes and formulates global cybersecurity processes and systems. The approach facilitates the way professionals navigate their way in the complex, evolving web of hardware and software vulnerabilities.
Keywords:
common vulnerabilities and exposures (CVE)
conceptual modeling
cybersecurity
knowledge representation
OPM ISO 19450
Journal
S
IF:
1.6
Papers:
48
Citations:
0

