VulLibGen: Generating Names of Vulnerability-Affected Packages via a Large Language Model

Tianyu Chen,Lin Li,Liuchuan Zhu,Zongyang Li,Xueqing Liu,Guangtai Liang,Qianxiang Wang,Tao Xie
2024-05-18
Abstract:Security practitioners maintain vulnerability reports (e.g., GitHub Advisory) to help developers mitigate security risks. An important task for these databases is automatically extracting structured information mentioned in the report, e.g., the affected software packages, to accelerate the defense of the vulnerability ecosystem.
Cryptography and Security
What problem does this paper attempt to address?