A Security Vulnerability Threat Classification Method.

Yuanwei Hou,Xingzhang Ren,Yongle Hao,Tong Mo,Weiping Li
DOI: https://doi.org/10.1007/978-3-319-69811-3_38
2018-01-01
Abstract:In the management and assessment of security vulnerabilities, it is always involving the task of threat classification. The traditional method requires the professional security management personnel to assess the vulnerability by analyzing the factors of access paths, the complexity, influence degree (confidentiality, integrity, availability) and the others. Due to the huge number and constantly generated security vulnerabilities, it needs a lot of professionals to manage, so that it may be due to the different subjective judgment criteria, judgment mistakes, lacking knowledge, etc., which caused the inconsistent, incorrect and inaccurate classification result of security vulnerabilities. In this paper, a GBDT based security vulnerability threat classification method is proposed, and effective features are extracted from semi-structured vulnerability description. In the experimental part, the supervised classification experiment was carried out by using the CNNVD (China National Vulnerability Database) from 1988 to the present which was manually annotated. The experimental results show that the proposed method has a good practical effect.
What problem does this paper attempt to address?