Automated event extraction of CVE descriptions
Automated event extraction of CVE descriptions
复制标题
DOI:
10.1016/j.infsof.2023.107178
复制
发表时间:
2023-02
期刊:
影响因子:
--
通讯作者:
Ying Wei;Lili Bo;Xiaobing Sun;Bin Li;Zhang Tao;Chuanqi Tao
中科院分区:
文献类型:
--
作者:
Ying Wei;Lili Bo;Xiaobing Sun;Bin Li;Zhang Tao;Chuanqi Tao
ContextThe dramatically increasing number of vulnerabilities makes manual vulnerability analysis increasingly more difficult. Automatic extraction of vulnerability information can help improve vulnerability analysis. However, the existing vulnerability information extraction methods do not extract from the perspective of events, and the existing event extraction methods do not consider the unique sentence structure characteristics of vulnerability descriptions, which makes it difficult to extract vulnerability information effectively.ObjectiveTo extract vulnerability information, we treat each vulnerability as an event, and propose an approach,VE-Extractor, to automatically perform vulnerability event extraction from textual descriptions in vulnerability reports for vulnerability analysis, including extraction of vulnerability event trigger (cause) and event arguments (e.g., consequence, operation).MethodFirst, we propose a new labeling method BIOFR (Begin, Inside, Outside, Front, Rear) to construct an event-perspective vulnerability data benchmark. Then, we design a question template based on event trigger, to automatically extract vulnerability event arguments through the BERT Q&A model.ResultsExperiments show the effectiveness ofVE-Extractorfor automatically extracting events from vulnerability description, with significant performance improvement over state-of-the-art techniques, e.g., F1-score is increased by 45.12% and 21.02% in vulnerability consequence and operation extraction, respectively.ConclusionThe proposedVE-Extractorachieves a higher precision and accuracy than the state-of-the-art methods. Experiments results show that our approach is effective in extracting vulnerability event information and can be used to assist vulnerability analysis, such as vulnerability classification.