Automated event extraction of CVE descriptions

Automated event extraction of CVE descriptions
复制标题

DOI:
10.1016/j.infsof.2023.107178
复制
发表时间:
2023-02
期刊:
Inf. Softw. Technol.
影响因子:
--
通讯作者:
Ying Wei;Lili Bo;Xiaobing Sun;Bin Li;Zhang Tao;Chuanqi Tao
Ying Wei;Lili Bo;Xiaobing Sun;Bin Li;Zhang Tao;Chuanqi Tao
中科院分区:
其他
文献类型:
--
作者:
Ying Wei;Lili Bo;Xiaobing Sun;Bin Li;Zhang Tao;Chuanqi Tao

文献摘要

相似文献

漏洞数量的急剧增加使得手动漏洞分析变得越来越困难。漏洞信息的自动提取有助于改进漏洞分析。然而,现有的漏洞信息提取方法没有从事件的角度进行提取,并且现有的事件提取方法没有考虑漏洞描述的独特的句子结构特征,这使得漏洞信息的有效提取变得困难。为了提取漏洞信息,我们将每个漏洞都视为一个事件,并提出了一种方法VE-Extractor,为了从弱点报告中的文本描述自动执行弱点事件提取以用于弱点分析,包括弱点事件触发器(原因)和事件参数(例如,方法首先,我们提出了一种新的标记方法BIOFR(开始,内部,外部,前面,后面)来构建事件视角的漏洞数据基准。然后,设计了一个基于事件触发器的问题模板,通过BERT Q&A模型自动提取漏洞事件参数。结果实验表明,VE-Extractor能够有效地从漏洞描述中自动提取事件,与现有技术相比,F1分数分别提高了45.12%和21.02%.ConclusionThe建议VE提取器实现了更高的精度和准确性比国家的最先进的方法。实验结果表明,我们的方法可以有效地提取漏洞事件信息,并可用于辅助漏洞分析,例如漏洞分类。
ContextThe dramatically increasing number of vulnerabilities makes manual vulnerability analysis increasingly more difficult. Automatic extraction of vulnerability information can help improve vulnerability analysis. However, the existing vulnerability information extraction methods do not extract from the perspective of events, and the existing event extraction methods do not consider the unique sentence structure characteristics of vulnerability descriptions, which makes it difficult to extract vulnerability information effectively.ObjectiveTo extract vulnerability information, we treat each vulnerability as an event, and propose an approach,VE-Extractor, to automatically perform vulnerability event extraction from textual descriptions in vulnerability reports for vulnerability analysis, including extraction of vulnerability event trigger (cause) and event arguments (e.g., consequence, operation).MethodFirst, we propose a new labeling method BIOFR (Begin, Inside, Outside, Front, Rear) to construct an event-perspective vulnerability data benchmark. Then, we design a question template based on event trigger, to automatically extract vulnerability event arguments through the BERT Q&A model.ResultsExperiments show the effectiveness ofVE-Extractorfor automatically extracting events from vulnerability description, with significant performance improvement over state-of-the-art techniques, e.g., F1-score is increased by 45.12% and 21.02% in vulnerability consequence and operation extraction, respectively.ConclusionThe proposedVE-Extractorachieves a higher precision and accuracy than the state-of-the-art methods. Experiments results show that our approach is effective in extracting vulnerability event information and can be used to assist vulnerability analysis, such as vulnerability classification.