Using Federated Learning to Predict Vulnerability Exploitability

Wangyuan Jing,Lingbo Wei,Hao Jin,Chi Zhang,Wenxiang Dong,Yangyang Li
DOI: https://doi.org/10.1109/hoticn57539.2022.10036231
2022-01-01
Abstract:The dramatic increase in the number of vulnerabilities and threats prompts the development of vulnerability exploitability prediction research. However, the existing vulnerability exploitability prediction research directly aggregates all vulnerability data without considering the security of vulnerability information, which leads to some problems such as data leakage and data island. In this paper, we propose a method for vulnerability exploitability prediction based on federated learning, which aims to achieve vulnerability exploitability prediction while protecting the security of vendor vulnerability data. Specifically, we first construct a vulnerability exploitability prediction model in a federated learning environment and classify the collected vulnerability data by vendors. Second, we evaluate multiple vulnerability exploitability prediction models and improve existing models. Finally, extensive experiments demonstrate that our proposed model achieves good results in the federated learning environment.
What problem does this paper attempt to address?