Identifying characteristics of software vulnerabilities by their textual description using machine learning
At a glance
- الاستشهادات
- 5
- المراجع
- 50
- Comments
- 0
Abstract
Significant problems in the development of secure software are the complexity of formalizing software vulnerabilities and the lack of information security experts. The paper tests the hypothesis that it is possible to automate the process of identifying vulnerability characteristics. The method based on a proprietary scheme for classifying vulnerabilities and specialized for the Russia Government Database of Vulnerabilities is presented. The method classifies vulnerability characteristics (hazard level field) based on a human-centered description of the vulnerability (name field and details field) using a multiclass SVM model. Utility implementing the method was developed. A number of experiments were carried out using the utility: the calculation of the method quality, a random classification mode, and a multi-pass approach to collect statistical data on the quality of work. The paper substantiates the confirmation of the hypothesis of scientific research. The scheme of the method is described in an analytical form, the main algorithm of the utility operation and the experiment logs are given.
Publication details
- DOI
- 10.23919/wac50355.2021.9559470
- OpenAlex
- W3205684496
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.