Vulnerability Detection for software-intensive system

被引:0
|
作者
Othman, Refat [1 ]
机构
[1] Free Univ Bozen Bolzano, Bolzano, Bolzano, Italy
关键词
ATT&CK; CAPEC; CWE; CVE; Transformer models; Pretrained language models;
D O I
10.1145/3661167.3661170
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cyberattacks are becoming more sophisticated, and organizations are constantly under threat from various types of security breaches. To protect against these threats, it is essential to identify the vulnerability and impact of these weaknesses and address them before attackers can exploit them. However, manually identifying and characterizing vulnerability can be a time-consuming and tedious process that adds to the workload of cybersecurity experts. To address this challenge, this research plan presents a doctoral research proposal to automate the process of identifying novel technologies, including learning-based technologies, to infer vulnerabilities from a text about an attack. In addition, this research plan uses natural language processing techniques to extract relevant information from attack text and analyze repositories for known vulnerabilities. This research plan presents an in-depth analysis of the research challenges and goals to understand how innovative technologies can be used to detect and identify vulnerabilities in text about attacks. It also covers the preliminary work done, literature review findings, and threats to validity.
引用
收藏
页码:510 / 515
页数:6
相关论文
共 50 条
  • [31] Evaluating performance in the development of software-intensive products
    Cedergren, Stefan
    Larsson, Stig
    INFORMATION AND SOFTWARE TECHNOLOGY, 2014, 56 (05) : 516 - 526
  • [32] Model checking for dependable software-intensive systems
    Clarke, E
    Fujita, M
    Gluch, D
    2003 INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2003, : 764 - 764
  • [33] A blueprint for system-level performance modeling of software-intensive embedded systems
    Hendriks, Martijn
    Basten, Twan
    Verriet, Jacques
    Brasse, Marco
    Somers, Lou
    INTERNATIONAL JOURNAL ON SOFTWARE TOOLS FOR TECHNOLOGY TRANSFER, 2016, 18 (01) : 21 - 40
  • [34] A blueprint for system-level performance modeling of software-intensive embedded systems
    Martijn Hendriks
    Twan Basten
    Jacques Verriet
    Marco Brassé
    Lou Somers
    International Journal on Software Tools for Technology Transfer, 2016, 18 : 21 - 40
  • [35] Safety Assessment of Complex, Software-Intensive Systems
    Leveson, Nancy G.
    Fleming, Cody Harrison
    Spencer, Melissa
    Thomas, John
    Wilkinson, Chris
    SAE INTERNATIONAL JOURNAL OF AEROSPACE, 2012, 5 (01): : 233 - 244
  • [36] Understanding the trust of software-intensive distributed systems
    Gallege, Lahiru S.
    Gamage, Dimuthu U.
    Hill, James H.
    Raje, Rajeev R.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2016, 28 (01): : 114 - 143
  • [37] Redefining Reliability Evaluations for Software-Intensive Systems
    Jais, Megan K.
    2015 61ST ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM (RAMS 2015), 2015,
  • [38] A Study of Resilient Architecture for Critical Software-Intensive System-of-Systems (Sisos)
    Akhtar, Nadeem
    Missen, Malik Muhammad Saad
    Salamat, Nadeem
    Firdous, Amnah
    Husnain, Mujtaba
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (08) : 254 - 258
  • [39] Systems Engineering Perspectives on Technology Readiness Assessments in Software-Intensive System Development
    Hantos, Peter
    JOURNAL OF AIRCRAFT, 2011, 48 (03): : 738 - 748
  • [40] Architecturally Describing the Emergent Behavior of Software-intensive System-of-Systems with SosADL
    Oquendo, Flavio
    2017 12TH SYSTEM OF SYSTEMS ENGINEERING CONFERENCE (SOSE), 2017,