ASVC: An Automatic Security Vulnerability Categorization Framework Based on Novel Features of Vulnerability Data

نویسندگان

  • Tao Wen
  • Yuqing Zhang
  • Qianru Wu
  • Gang Yang
چکیده

— Security vulnerabilities are a main cause of network security. Vulnerability classification gives us a better understanding of the essence of vulnerabilities, which help propose efficient solutions. However, applying Vulnerability Categorization Standard (VCS) to manually categorize vulnerabilities is impracticable since it is time-consuming and subjective. To address this issue, a new framework named Automatic Security Vulnerabilities Categorization Framework (ASVC) is proposed based on Text Mining. To further improve the accuracy, a new rule for extraction of features of Text Mining is proposed. ASVC abstracts the categorization of vulnerabilities into a process of Text Mining, and categorize vulnerabilities automatically according to a VCS. Finally, VCS of Common Weakness Enumeration is applied to three main Vulnerability Databases based on ASVC in a fast way, about 1000 vulnerabilities per hour. The accuracy of the categorization is 86.8%, 8.3% higher than previous works.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Novel Automatic Severity Vulnerability Assessment Framework

—Security vulnerabilities play an important role in network security. With the development of the network and the increasing number of vulnerabilities, many Quantitative Vulnerability Assessment Standards (QVAS) was proposed in order to enable professionals to prioritize the most important vulnerabilities with limited energy. However, it is difficult to apply QVAS manually due to the large num...

متن کامل

Spatial Assessment of Regional Environmental Vulnerability for Environmental Planning in the Eastern Region of Urmia Lake

     Environment, development and sustainability are the three significant issues of worldwide concern. Environmental vulnerability and assessment of natural and anthropogenic activities impacts represent a comprehensive evaluation approach. The main purpose of this study is to present a comprehensive and novel framework in order to environmental vulnerability assessment using by spatial data a...

متن کامل

Evaluation of Ecological Vulnerability in Chelgard Mountainous Landscape

Although complexity and vulnerability assessment of mountain landscapes is increasingly taken into consideration, less attention is paid to ecophronesis-based solutions so as to reduce the fragile ecosystem vulnerability. The main propose of this study is to provide an insight of mountain complex landscape vulnerability and propose ecophronesis-based solutions in strategic planning framework fo...

متن کامل

A Novel Network Modeling and Evaluation Approach for Security Vulnerability Quantification in Substation Automation Systems

With the proliferation of smart grids and the construction of various electric IT systems and networks, a next-generation substation automation system (SAS) based on IEC 61850 has been agreed upon as a core element of smart grids. However, research on security vulnerability analysis and quantification for automated substations is still in the preliminary phase. In particular, it is not suitable...

متن کامل

Automated Vulnerability Management of Computer Systems

With the continuous flood of vulnerabilities of computer systems, vulnerability management is a very important task for administrators to keep systems as secure as possible. However current manual vulnerability management by administrators is very time-consuming and error-prone. This paper proposes an open framework of automated vulnerability management that dramatically alleviates the burden o...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • JCM

دوره 10  شماره 

صفحات  -

تاریخ انتشار 2015