Predicting Cybersecurity Vulnerability Severity via Boosted Machine Learning Ensembles and Feature Ranking
Open AccessThousands of software weaknesses are identified every year and publicly reported. These weaknesses—also known as vulnerabilities—are given Common Vulnerability and Exposure (CVE) identification numbers. The CVEs are analyzed using the Common Vulnerabilities Scoring System (CVSS) metrics to produce corresponding severity categories published in a repository managed by the U.S. government, the National Vulnerability Database (NVD). The NVD data help drive informed decisions on what vulnerabilities need to be prioritized for remediation. The number of CVEs identified have steadily increased, rising 34% since 2015. The median time taken to analyze and populate the NVD has also increased from one to 19 days. Vulnerabilities need to be analyzed, prioritized based on severity ratings, and remediated as quickly as possible to prevent cybersecurity incidents such as data breaches, ransomware attacks, and so forth. Other related research studies have focused on analyses, exploitability predictions using selected Machine Learning (ML) techniques, comparisons with other known vulnerability sources, and so forth, using CVSS version 2 metrics data. This research will use updated data focusing on CVSS version 3 metrics and introducing a predictive model that uses boosted ML algorithms and ensembles for cybersecurity severity categorizations. Classification and Regression Tree algorithms are used to analyze and rank influential CVSS metrics. The model could be used in organizations to facilitate vulnerability management activities affecting technology assets, such as cyber risk evaluations and forecasting.Keywords: Cybersecurity, CVSS, Predictive model, , Feature ranking, Vulnerability Management
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.
| Thumbnail | Title | Date Uploaded | Visibility | Actions |
|---|---|---|---|---|
|
|
Ohuabunwa_gwu_0075A_15797.pdf | 2022-03-06 | Open Access |
|