Predicting Vulnerability Type in Common Vulnerabilities and Exposures (CVE) Database with Machine Learning Classifiers


연구 분야: Strategies



학회: 2021 12th National Conference with International Participation (ELECTRONICA)


초록

Vulnerability type is not part of the standard CVE scheme so the ability to determine it only on the basis of text description would be a very useful for automated vulnerability handling. The growing number of hardware and software vulnerabilities discovered every year makes it more difficult for manual classification of the vulnerabilities types. This justifies the need for automatic machine learning classification. In this study we research the performance of base ML classifier algorithms, such as Linear Support Vector Classification, Naive Bayes, and Random Forest Classifier. To measure the performance of our classifiers, we use precision, recall, and f1-score evaluation metrics. Previous studies have focused on machine learning methods predicting platform vendor and products, vulnerability scoring, software vulnerabilities exploitation. Our study aims to show that machine learning is suitable for automated vulnerability type classification.


Author Profile
Veneta Yosifova

Faculty of Computer Systems and Technologies Technical University of Sofia Sofia Bulgaria

Andorra
Author Profile
Antoniya Tasheva

Faculty of Computer Systems and Technologies Technical University of Sofia Sofia Bulgaria

Andorra
Author Profile
Roumen Trifonov

Faculty of Computer Systems and Technologies Technical University of Sofia Sofia Bulgaria

Andorra

📄 논문 정보

발행 연도 2021년
인용수 26
출판 국가 Andorra
사이트 IEEE
좋아요 수 0

연관 논문 목록 (208건)