共 6 条
Identifying missing relationships of CAPEC attack patterns by transformer models and graph structure
被引:2
|作者:
Miyata, Rikuho
[1
]
Washizaki, Hironori
[1
]
Sumoto, Kensuke
[1
]
Yoshioka, Nobukazu
[1
]
Fukazawa, Yoshiaki
[1
]
Okubo, Takao
[2
]
机构:
[1] Waseda Univ, Tokyo, Japan
[2] Inst Informat Secur, Yokohama, Japan
关键词:
CAPEC;
relation prediction;
Transformer;
BERT;
Longformer;
D O I:
10.1109/SVM59160.2023.00008
中图分类号:
TP [自动化技术、计算机技术];
学科分类号:
0812 ;
摘要:
As threats to software vulnerabilities diversify, countermeasures against various threat patterns become more critical. The Common Attack Pattern Enumeration and Classification (CAPEC) is a catalog of security attack patterns that helps understand what attacks can be launched against these vulnerabilities. CAPEC defines relationships between attack patterns, but these are manually associated so that some may be missed. This paper proposes a method to identify missed relationships using the transformer model and existing relational graph structures. Specifically, pre-trained models are fine-tuned using BERT and Longformer based on the names and descriptions of the two attack patterns and their relationships. Then missed relationships are identified by the classification task, and graph structure rules are defined for the identified relations to determine whether they are graph-structurally correct. Finally, whether the relations are semantically correct is verified. Our evaluation found that 41 likely relationships were missed.
引用
收藏
页码:14 / 17
页数:4
相关论文