Deterministic Network Vulnerability Test Generation Through Predictable Template Learning: A Systematic Evaluation
At a glance
- Citations
- 0
- References
- 7
- Comments
- 0
Öz
Network vulnerability assessment relies heavily on Nessus Attack Scripting Language scripts for automated security testing. Traditional approaches to generating these specialized security scripts face significant challenges in maintaining syntactic correctness and semantic relevance. This paper introduces a novel predictable template learning methodology that transforms non-deterministic Common Vulnerabilities and Exposures descriptions into deterministic Nessus Attack Scripting Language code generation through systematic placeholder preprocessing. We fine-tune DeepSeek Coder 6.7B using Low-Rank Adaptation on a carefully curated dataset of 99,143 Common Vulnerabilities and Exposures-Nessus Attack Scripting Language pairs, implementing template-based preprocessing to replace unpredictable elements with consistent placeholders. Our resulting fine-tuned model, NASLGenDSC, achieves 86 % training loss reduction with a final perplexity of 1.17 compared to zero-shot approaches. Comprehensive baseline evaluations against DeepSeek Coder, CodeLlama 7B, and StarCoder2 7B show our approach achieves 30-43% lower perplexity across 300 test evaluations, validating the effectiveness of template learning for security-critical code generation. The deterministic nature of our output enables practical deployment in production vulnerability management systems.
Publication details
- DOI
- 10.1109/icdmw69685.2025.00142
- OpenAlex
- W7134966833
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Oturum Açın to join the discussion.