The identification of vulnerabilities is a continuous challenge in software projects. This is due to the evolution of methods that attackers employ as well as the constant updates to the software, which reveal additional issues. As a result, new and innovative approaches for the identification of vulnerable software are needed. In this paper, we present VULNERLIZER, which is a novel framework for cross-analysis between vulnerabilities and software libraries. It uses CVE and software library data together with clustering algorithms to generate links between vulnerabilities and libraries. In addition, the training of the model is conducted in order to reevaluate the generated associations. This is achieved by updating the assigned weights. Finally, the approach is then evaluated by making the predictions using the CVE data from the test set. The results show that the VULNERLIZER has a great potential in being able to predict future vulnerable libraries based on an initial input CVE entry or a software library. The trained model reaches a prediction accuracy of 75% or higher.
翻译:漏洞识别是软件项目中持续存在的挑战,这源于攻击者所用方法的演变以及软件持续更新所暴露的额外问题。因此,亟需创新性方法来识别易受攻击的软件。本文提出VULNERLIZER,一种用于漏洞与软件库之间交叉分析的新型框架。该框架利用CVE(通用漏洞披露)数据、软件库数据以及聚类算法,生成漏洞与软件库之间的关联。此外,通过更新分配的权重对模型进行训练,以重新评估生成的关联。最后,使用测试集中的CVE数据进行预测以评估方法性能。结果表明,VULNERLIZER能够基于初始输入的CVE条目或软件库,有效预测未来可能受影响的软件库。经训练后的模型预测准确率达到75%或更高。