VASE: A Twitter-based Vulnerability Analysis and Score Engine

被引:7
|
作者
Chen, Haipeng [1 ]
Liu, Jing [2 ]
Liu, Rui [1 ]
Park, Noseong [2 ]
Subrahmanian, V. S. [1 ]
机构
[1] Dartmouth Coll, Hanover, NH 03755 USA
[2] George Mason Univ, Fairfax, VA 22030 USA
关键词
Vulnerability Severity Prediction; Social Media Data Mining; Graph Convolution Networks; Input Embedding;
D O I
10.1109/ICDM.2019.00110
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
When a new vulnerability is discovered, a Common Vulnerability and Exposure (CVE) number is publicly assigned to it. The vulnerability is then analyzed by the US National Institute of Standards and Technology (NIST) whose Common Vulnerability Scoring System (CVSS) evaluates a severity score that ranges from 0 to 10 for the vulnerability(1). On average, NIST takes 132.7 days for this - but early knowledge of the CVSS score is critical for enterprise security managers to take defensive actions (e.g. patch prioritization). We present VASE (Vulnerability Analysis and Scoring Engine) that uses Twitter discussions about CVEs to predict CVSS scores before the official assessments from NIST. In order to leverage the intrinsic correlations between different vulnerabilities, VASE adopts a graph convolutional network (GCN) model in which nodes correspond to CVEs. In addition, we propose a novel attention-based input embedding method to extract useful latent features for each CVE node. We show on real-world data that VASE obtains a mean absolute error (MAE) of 1.255 for predicting the CVSS score using only three days of Twitter discussion data after the date a vulnerability is first mentioned on Twitter. VASE can provide predictions for the CVSS scores for 37.85% of the CVEs at least one week earlier than the official assessments by NIST.
引用
收藏
页码:982 / 987
页数:6
相关论文
共 50 条
  • [1] TEDAS: a Twitter-based Event Detection and Analysis System
    Li, Rui
    Lei, Kin Hou
    Khadiwala, Ravi
    Chang, Kevin Chen-Chuan
    2012 IEEE 28TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE), 2012, : 1273 - 1276
  • [2] Twitter-Based Social Accountability Callouts
    Dean Neu
    Gregory D. Saxton
    Journal of Business Ethics, 2024, 189 : 797 - 815
  • [3] THE NEXUS BETWEEN TWITTER-BASED UNCERTAINTY AND CRYPTOCURRENCIES: A MULTIFRACTAL ANALYSIS
    Aslam, Faheem
    Zil-E-Huma
    Bibi, Rashida
    Ferreira, Paulo
    FRACTALS-COMPLEX GEOMETRY PATTERNS AND SCALING IN NATURE AND SOCIETY, 2023, 31 (03)
  • [4] TWITTER-BASED EFL PRONUNCIATION INSTRUCTION
    Antonio Mompean, Jose
    Fouz-Gonzalez, Jonas
    LANGUAGE LEARNING & TECHNOLOGY, 2016, 20 (01): : 166 - 190
  • [5] Twitter-based analysis of anti-refugee discourses in Turkiye
    Yilmaz, Fahri
    Elmas, Tugay
    Eroz, Betil
    DISCOURSE & COMMUNICATION, 2023, 17 (03) : 298 - 318
  • [6] Twitter-Based Analysis of the Dynamics of Collective Attention to Political Parties
    Eom, Young-Ho
    Puliga, Michelangelo
    Smailovic, Jasmina
    Mozetic, Igor
    Caldarelli, Guido
    PLOS ONE, 2015, 10 (07):
  • [7] Twitter-Based Social Accountability Callouts
    Neu, Dean
    Saxton, Gregory D. D.
    JOURNAL OF BUSINESS ETHICS, 2024, 189 (04) : 797 - 815
  • [8] A Twitter-Based Weighted Reputation system
    Jeragh, Mohammad
    AlQuraishi, Eman
    AlDwaisan, Eman
    ANT 2012 AND MOBIWIS 2012, 2012, 10 : 902 - 908
  • [9] Demographics of Twitter-Based Toxicology Learners
    Chai, Peter
    Griswold, Matthew
    Hayes, Bryan
    Gussow, Leon
    Juurlink, David
    Boyer, Edward
    Babu, Kavita
    CLINICAL TOXICOLOGY, 2016, 54 (08) : 783 - 783
  • [10] Twitter-Based uncertainty and cryptocurrency returns
    Aharon, David Y.
    Demir, Ender
    Lau, Chi Keung Marco
    Zaremba, Adam
    RESEARCH IN INTERNATIONAL BUSINESS AND FINANCE, 2022, 59