VASE: A Twitter-based Vulnerability Analysis and Score Engine

被引:7
|
作者
Chen, Haipeng [1 ]
Liu, Jing [2 ]
Liu, Rui [1 ]
Park, Noseong [2 ]
Subrahmanian, V. S. [1 ]
机构
[1] Dartmouth Coll, Hanover, NH 03755 USA
[2] George Mason Univ, Fairfax, VA 22030 USA
关键词
Vulnerability Severity Prediction; Social Media Data Mining; Graph Convolution Networks; Input Embedding;
D O I
10.1109/ICDM.2019.00110
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
When a new vulnerability is discovered, a Common Vulnerability and Exposure (CVE) number is publicly assigned to it. The vulnerability is then analyzed by the US National Institute of Standards and Technology (NIST) whose Common Vulnerability Scoring System (CVSS) evaluates a severity score that ranges from 0 to 10 for the vulnerability(1). On average, NIST takes 132.7 days for this - but early knowledge of the CVSS score is critical for enterprise security managers to take defensive actions (e.g. patch prioritization). We present VASE (Vulnerability Analysis and Scoring Engine) that uses Twitter discussions about CVEs to predict CVSS scores before the official assessments from NIST. In order to leverage the intrinsic correlations between different vulnerabilities, VASE adopts a graph convolutional network (GCN) model in which nodes correspond to CVEs. In addition, we propose a novel attention-based input embedding method to extract useful latent features for each CVE node. We show on real-world data that VASE obtains a mean absolute error (MAE) of 1.255 for predicting the CVSS score using only three days of Twitter discussion data after the date a vulnerability is first mentioned on Twitter. VASE can provide predictions for the CVSS scores for 37.85% of the CVEs at least one week earlier than the official assessments by NIST.
引用
收藏
页码:982 / 987
页数:6
相关论文
共 50 条
  • [31] The impact of Twitter-based sentiment on US sectoral returns
    Zeitun, Rami
    Rehman, Mobeen Ur
    Ahmad, Nasir
    Vo, Xuan Vinh
    NORTH AMERICAN JOURNAL OF ECONOMICS AND FINANCE, 2023, 64
  • [32] Twitter-Based Safety Confirmation System for Disaster Situations
    Utsu, Keisuke
    Abe, Mariko
    Nishikawa, Shuji
    Uchida, Osamu
    FUTURE INTERNET, 2020, 12 (01):
  • [33] Twitter-based selection of topics that users are interested in but are not familiar with
    Sakai, Yuya
    Matsumoto, Mitsuharu
    2021 IEEE/SICE INTERNATIONAL SYMPOSIUM ON SYSTEM INTEGRATION (SII), 2021, : 769 - 774
  • [34] Twitter-Based Journal Clubs: Additional Facts and Clarifications
    Topf, Joel M.
    Sparks, Matthew A.
    Iannuzzella, Francesco
    Lerma, Edgar
    Oates, Thomas
    Phelan, Paul J.
    Hiremath, Swapnil
    JOURNAL OF MEDICAL INTERNET RESEARCH, 2015, 17 (09)
  • [35] Twitter-based Polarised Embeddings for Abusive Language Detection
    Graumas, Leon
    David, Roy
    Caselli, Tommaso
    2019 8TH INTERNATIONAL CONFERENCE ON AFFECTIVE COMPUTING AND INTELLIGENT INTERACTION WORKSHOPS AND DEMOS (ACIIW), 2019, : 198 - 204
  • [36] An English-Japanese Twitter-Based Analysis of Disaster Sentiment during Typhoons and Earthquakes
    Detera, Bernadette Joy
    Kodaka, Akira
    Kohtake, Naohiko
    Nishino, Akihiko
    Onda, Kaya
    7TH IEEE INTERNATIONAL SYMPOSIUM ON SYSTEMS ENGINEERING (IEEE ISSE 2021), 2021,
  • [37] The Social Aspects of Sexual Health: A Twitter-Based Analysis of Valentine's Day Perception
    Sansone, Andrea
    Cignarelli, Angelo
    Mollaioli, Daniele
    Ciocca, Giacomo
    Limoncin, Erika
    Romanelli, Francesco
    Balercia, Giancarlo
    Jannini, Emmanuele A.
    SEXES, 2021, 2 (01): : 50 - 59
  • [38] Assessment of public perceptions and concerns of celiac disease: A Twitter-based sentiment analysis study
    Trovato, Chiara Maria
    Montuori, Monica
    Oliva, Salvatore
    Cucchiara, Salvatore
    Cignarelli, Angelo
    Sansone, Andrea
    DIGESTIVE AND LIVER DISEASE, 2020, 52 (04) : 464 - 466
  • [39] Design of a Classification Model for a Twitter-based Streaming Threat Monitor
    Alves, Fernando
    Ferreira, Pedro M.
    Bessani, Alysson
    2019 49TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS (DSN-W), 2019, : 9 - 14
  • [40] Incorporating twitter-based human activity information in spatial analysis of crashes in urban areas
    Bao, Jie
    Liu, Pan
    Yu, Hao
    Xu, Chengcheng
    ACCIDENT ANALYSIS AND PREVENTION, 2017, 106 : 358 - 369