VASE: A Twitter-based Vulnerability Analysis and Score Engine

被引:7
|
作者
Chen, Haipeng [1 ]
Liu, Jing [2 ]
Liu, Rui [1 ]
Park, Noseong [2 ]
Subrahmanian, V. S. [1 ]
机构
[1] Dartmouth Coll, Hanover, NH 03755 USA
[2] George Mason Univ, Fairfax, VA 22030 USA
关键词
Vulnerability Severity Prediction; Social Media Data Mining; Graph Convolution Networks; Input Embedding;
D O I
10.1109/ICDM.2019.00110
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
When a new vulnerability is discovered, a Common Vulnerability and Exposure (CVE) number is publicly assigned to it. The vulnerability is then analyzed by the US National Institute of Standards and Technology (NIST) whose Common Vulnerability Scoring System (CVSS) evaluates a severity score that ranges from 0 to 10 for the vulnerability(1). On average, NIST takes 132.7 days for this - but early knowledge of the CVSS score is critical for enterprise security managers to take defensive actions (e.g. patch prioritization). We present VASE (Vulnerability Analysis and Scoring Engine) that uses Twitter discussions about CVEs to predict CVSS scores before the official assessments from NIST. In order to leverage the intrinsic correlations between different vulnerabilities, VASE adopts a graph convolutional network (GCN) model in which nodes correspond to CVEs. In addition, we propose a novel attention-based input embedding method to extract useful latent features for each CVE node. We show on real-world data that VASE obtains a mean absolute error (MAE) of 1.255 for predicting the CVSS score using only three days of Twitter discussion data after the date a vulnerability is first mentioned on Twitter. VASE can provide predictions for the CVSS scores for 37.85% of the CVEs at least one week earlier than the official assessments by NIST.
引用
收藏
页码:982 / 987
页数:6
相关论文
共 50 条
  • [41] Stream ETL framework for twitter-based sentiment analysis: Leveraging big data technologies
    Ismail, Azlan
    Sazali, Faris Haziq
    Jawaddi, Siti Nuraishah Agos
    Mutalib, Sofianita
    EXPERT SYSTEMS WITH APPLICATIONS, 2025, 261
  • [42] Current Social Media Conversations about Genetics and Genomics in Health: A Twitter-Based Analysis
    Allen, Caitlin G.
    Andersen, Brittany
    Khoury, Muin J.
    Roberts, Megan C.
    PUBLIC HEALTH GENOMICS, 2018, 21 (1-2) : 93 - 99
  • [43] Investigating Remote Work Trends in Post-COVID-19: A Twitter-Based Analysis
    Korkmaz, Adem
    Bulut, Selma
    Kosunalp, Selahattin
    Iliev, Teodor
    IEEE ACCESS, 2024, 12 : 196954 - 196968
  • [44] Measuring The Impact of a Twitter-Based Educational Initiative: The #EmoryNCCTweetorials Project
    Sigman, Erika
    Pimentel, Cederic
    Kandiah, Prem
    Lawson, Eric
    Albin, Casey
    NEUROLOGY, 2023, 100 (17)
  • [45] Twitter-Based Detection of Illegal Online Sale of Prescription Opioid
    Mackey, Tim K.
    Kalyanam, Janani
    Katsuki, Takeo
    Lanckriet, Gert
    AMERICAN JOURNAL OF PUBLIC HEALTH, 2017, 107 (12) : 1910 - 1915
  • [46] Twitter-based traffic delay detection based on topic propagation analysis using railway network topology
    Wang, Yuanyuan
    Siriaraya, Panote
    Kawai, Yukiko
    Akiyama, Toyokazu
    PERSONAL AND UBIQUITOUS COMPUTING, 2019, 23 (02) : 233 - 247
  • [47] Oil futures volatility predictability: Evidence based on Twitter-based uncertainty
    Lang, Qiaoqi
    Lu, Xinjie
    Ma, Feng
    Huang, Dengshi
    FINANCE RESEARCH LETTERS, 2022, 47
  • [48] TWITTER-BASED MULTIMODAL METAPHORICAL MEMES PORTRAYING DONALD TRUMP
    Martynyuk, Alla
    Meleshchenko, Olga
    LEGE ARTIS-LANGUAGE YESTERDAY TODAY TOMORROW, 2019, 4 (02): : 128 - 167
  • [49] Twitter-based Sensing of City-level Air Quality
    Charitidis, Polychronis
    Spyromitros-Xioufis, Eleftherios
    Papadopoulos, Symeon
    Kompatsiaris, Yiannis
    PROCEEDINGS 2018 IEEE 13TH IMAGE, VIDEO, AND MULTIDIMENSIONAL SIGNAL PROCESSING WORKSHOP (IVMSP), 2018,
  • [50] Considering a Twitter-Based Professional Learning Network in Literacy Education
    Colwell, Jamie
    Hutchison, Amy C.
    LITERACY RESEARCH AND INSTRUCTION, 2018, 57 (01) : 5 - 25