conference-paper

Prioritizing Vulnerability Assessment Items Using LLM Based on IoT Device Documentations

Research footprint

At a glance

Citations
5
References
11
Comments
0
Paper overview

Abstract

With the rapid increase in demand for IoT devices, malicious attacks targeting vulnerabilities in IoT devices have been frequent in recent years. It is highly expected that the vulnerabilities can be removed from them through vulnerability assessment. However, the wide variety of IoT devices is not standardized, and it is difficult to set up vulnerability assessment items mechanically for those IoT devices, which causes a major obstacle to automate the vulnerability assessment for IoT devices. In this paper, we propose a method to prioritize vulnerability assessment items for every IoT device by effectively utilizing a large language model (LLM). The proposed method generates the answers that take into account the specifications of individual IoT devices using LLM by introducing Retrieval Augmented Generation (RAG), and determines how much suitable each vulnerability assessment item is for every IoT device by calculating the suitability using semantic entropy. Performing security tests based on the suitability must improve time efficiency while maintaining the coverage of the tests. Through the evaluation experiments, we obtained a suitability of vulnerability assessment items for the two types of IoT devices, which indicates 0.8 or higher in both the devices in terms of area under the curve (AUC).

Record transparency

Publication details

DOI
10.1109/iotsms62296.2024.10710294
OpenAlex
W4403391076
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.