Cybersecurity Vulnerability Classification Utilizing Natural Language Processing Methods
Open AccessIn recent years there has been a significant increase in the number of disclosedcybersecurity vulnerabilities resulting in lengthy analysis delays, allowing for cyberattackers to exploit these vulnerabilities before pertinent data can be published to inform cybersecurity professionals (Elbaz, Rilling, & Morin, 2020). This data includes impact metrics, vulnerability types, and applicability statements. Previous research has focused on automatically predicting the Common Vulnerability Scoring System (CVSS) score calculated from impact metrics, as shown in the National Vulnerability Database (NVD) using methods such as term frequency-inverse document frequency (TF-IDF) (Wåreus & Hell, 2020; Khazei, Ghasemzadeh, & Derhami, 2015; Feutrill, Ranathunga, Yarom, & Roughan, 2018; Bullough, Yanchenko, Smith, & Zipkin, 2017). Any approach that reduces analysis delays also reduces the zero-day vulnerability window thereby decreasing the likelihood a vulnerability will be exploited. This research utilizes natural language processing (NLP), topic modeling, and transformer deep learning models also known as transformers to derive meaning from NVD vulnerability description texts to classify the vulnerabilities, with machine learning models trained with previous years’ data, by their individual CVSS base score metrics (exploitability and impact metrics). From this classification the total analysis time of future vulnerabilities will be reduced, and cybersecurity professionals will be able to make more informed decisions regarding vulnerability management of assets to aid in preventing future cyber-attacks from key vulnerability characteristics.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.
| Thumbnail | Title | Date Uploaded | Visibility | Actions |
|---|---|---|---|---|
|
|
Evangelista_gwu_0075A_15672.pdf | 2022-03-06 | Open Access |
|