VASE: A Twitter-based Vulnerability Analysis and Score Engine

被引:7
|
作者
Chen, Haipeng [1 ]
Liu, Jing [2 ]
Liu, Rui [1 ]
Park, Noseong [2 ]
Subrahmanian, V. S. [1 ]
机构
[1] Dartmouth Coll, Hanover, NH 03755 USA
[2] George Mason Univ, Fairfax, VA 22030 USA
关键词
Vulnerability Severity Prediction; Social Media Data Mining; Graph Convolution Networks; Input Embedding;
D O I
10.1109/ICDM.2019.00110
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
When a new vulnerability is discovered, a Common Vulnerability and Exposure (CVE) number is publicly assigned to it. The vulnerability is then analyzed by the US National Institute of Standards and Technology (NIST) whose Common Vulnerability Scoring System (CVSS) evaluates a severity score that ranges from 0 to 10 for the vulnerability(1). On average, NIST takes 132.7 days for this - but early knowledge of the CVSS score is critical for enterprise security managers to take defensive actions (e.g. patch prioritization). We present VASE (Vulnerability Analysis and Scoring Engine) that uses Twitter discussions about CVEs to predict CVSS scores before the official assessments from NIST. In order to leverage the intrinsic correlations between different vulnerabilities, VASE adopts a graph convolutional network (GCN) model in which nodes correspond to CVEs. In addition, we propose a novel attention-based input embedding method to extract useful latent features for each CVE node. We show on real-world data that VASE obtains a mean absolute error (MAE) of 1.255 for predicting the CVSS score using only three days of Twitter discussion data after the date a vulnerability is first mentioned on Twitter. VASE can provide predictions for the CVSS scores for 37.85% of the CVEs at least one week earlier than the official assessments by NIST.
引用
收藏
页码:982 / 987
页数:6
相关论文
共 50 条
  • [21] A Twitter-Based Study of the European Internet of Things
    Ustek-Spilda, Funda
    Vega, Davide
    Magnani, Matteo
    Rossi, Luca
    Shklovski, Irina
    Lehuede, Sebastian
    Powell, Alison
    INFORMATION SYSTEMS FRONTIERS, 2021, 23 (01) : 135 - 149
  • [22] A Twitter-based survey on marijuana concentrate use
    Daniulaityte, Raminta
    Zatreh, Mussa Y.
    Lamy, Francois R.
    Nahhas, Ramzi W.
    Martins, Silvia S.
    Sheth, Amit
    Carlson, Robert G.
    DRUG AND ALCOHOL DEPENDENCE, 2018, 187 : 155 - 159
  • [23] TweetCric: A twitter-based accountability mechanism for cricket
    Younus, Arjumand
    Qureshi, M. Atif
    Aljohani, Naif R.
    Greene, Derek
    O’Mahony, Michael P.
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2017, 10360 LNCS : 559 - 563
  • [24] TweetCric: A Twitter-Based Accountability Mechanism for Cricket
    Younus, Arjumand
    Qureshi, M. Atif
    Aljohani, Naif R.
    Greene, Derek
    O'Mahony, Michael P.
    WEB ENGINEERING (ICWE 2017), 2017, 10360 : 559 - 563
  • [25] Health Organizations Providing and Seeking Social Support: A Twitter-Based Content Analysis
    Rui, Jian Raymond
    Chen, Yixin
    Damiano, Amanda
    CYBERPSYCHOLOGY BEHAVIOR AND SOCIAL NETWORKING, 2013, 16 (09) : 669 - 673
  • [26] A Twitter-Based Comparative Analysis of Emotions and Sentiments of Arab and Hispanic Football Fans
    Alhadlaq, Aseel
    Alnuaim, Abeer
    APPLIED SCIENCES-BASEL, 2023, 13 (11):
  • [27] Socialbots: Implications on the safety and reliability of Twitter-based services
    Freitas, Carlos A.
    Benevenuto, Fabricio
    Veloso, Adriano
    2014 BRAZILIAN SYMPOSIUM ON COMPUTER NETWORKS AND DISTRIBUTED SYSTEMS (SBRC), 2014, : 302 - 309
  • [28] Mental health effects of COVID-19 lockdowns: A Twitter-based analysis
    Colella, Sara
    Dufourt, Frederic
    Hildebrand, Vincent A.
    Vives, Remi
    ECONOMICS & HUMAN BIOLOGY, 2023, 51
  • [29] Credibility Evaluation of Twitter-Based Event Detection by a Mixing Analysis of Heterogeneous Data
    Sato, Koichi
    Wang, Junbo
    Cheng, Zixue
    IEEE ACCESS, 2019, 7 : 1095 - 1106
  • [30] #Rheumjc: Development, Implementation and Analysis of an International Twitter-Based Rheumatology Journal Club
    Collins, Christopher
    Sufka, Paul
    Hausmann, Jonathan S.
    Jayatilleke, Arundathi
    Campos, Jose
    Bhana, Suleman
    ARTHRITIS & RHEUMATOLOGY, 2015, 67