V2W-BERT: A Framework for Effective Hierarchical Multiclass Classification of Software Vulnerabilities

V2W-BERT: A Framework for Effective Hierarchical Multiclass Classification of Software Vulnerabilities
复制标题

DOI:
10.1109/dsaa53316.2021.9564227
复制
发表时间:
2021-02
期刊:
2021 IEEE 8th International Conference on Data Science and Advanced Analytics (DSAA)
影响因子:
--
通讯作者:
Siddhartha Shankar Das;Edoardo Serra;M. Halappanavar;A. Pothen;E. Al-Shaer
Siddhartha Shankar Das;Edoardo Serra;M. Halappanavar;A. Pothen;E. Al-Shaer
中科院分区:
其他
文献类型:
--
作者:
Siddhartha Shankar Das;Edoardo Serra;M. Halappanavar;A. Pothen;E. Al-Shaer

文献摘要

被引文献

相似文献

我们认为,自动化的问题所观察到的漏洞在常见的漏洞和暴露(CVE)报告中列出的软件中的弱点,常见的弱点枚举(CWE)报告,分层设计的字典软件弱点。将CVE映射到CWE提供了一种了解它们如何被恶意利用并减轻其影响的方法。由于CVEs到CWE的手动映射由于其不断增加的尺寸而不是可行的方法,因此需要设计自动化方法,但是获得高度准确的映射是一个具有挑战性的问题。本文提出了一种新的基于transformer的学习框架(V2 W-BERT),通过融合自然语言处理,链接预测和迁移学习的思想来解决这个问题。我们的方法不仅在具有大量数据的CWE实例中优于以前的方法,而且在具有很少或没有数据的罕见CWE类中也优于以前的方法。使用MITRE和国家漏洞数据库的漏洞和弱点报告,我们实现了高达97%的随机分区数据和高达94%的时间分区数据的预测准确率预测。我们展示了显着的改进,使用历史数据来预测未来的CVE实例的弱点。我们相信,我们的工作将影响更好的自动映射方法的设计,并且这项技术可以用于更有效的网络安全。
We consider the problem of automating the mapping of observed vulnerabilities in software listed in Common Vulnerabilities and Exposures (CVE) reports to weaknesses listed in Common Weakness Enumerations (CWE) reports, a hierarchically designed dictionary of software weaknesses. Mapping of CVEs to CWEs provides a means to understand how they might be exploited for malicious purposes, and to mitigate their impact. Since manual mapping of CVEs to CWEs is not a viable approach due to their ever-increasing sizes, automated approaches need to be devised but obtaining highly accurate mapping is a challenging problem. We present a novel Transformer-based learning framework (V2W-BERT) in this paper to solve this problem by bringing together ideas from natural language processing, link prediction and transfer learning. Our method outperforms previous approaches not only for CWE instances with abundant data to train, but also for rare CWE classes with little or no data. Using vulnerability and weakness reports from MITRE and the National Vulnerability Database, we achieve up to 97% prediction accuracy for randomly partitioned data and up to 94% prediction accuracy in temporally partitioned data. We demonstrate significant improvements in using historical data to predict weaknesses for future instances of CVEs. We believe that our work will would influence the design of better automated mapping approaches, and also that this technology could be deployed for more effective cybersecurity.