Knowledge graphs have shown promise for several cybersecurity tasks, such as vulnerability assessment and threat analysis. In this work, we present a new method for constructing a vulnerability knowledge graph from information in the National Vulnerability Database (NVD). Our approach combines named entity recognition (NER), relation extraction (RE), and entity prediction using a combination of neural models, heuristic rules, and knowledge graph embeddings. We demonstrate how our method helps to fix missing entities in knowledge graphs used for cybersecurity and evaluate the performance.
@article{arxiv.2305.00382,
title = {Constructing a Knowledge Graph from Textual Descriptions of Software Vulnerabilities in the National Vulnerability Database},
author = {Anders Mølmen Høst and Pierre Lison and Leon Moonen},
journal= {arXiv preprint arXiv:2305.00382},
year = {2023}
}
Comments
Accepted for publication in the 24th Nordic Conference on Computational Linguistics (NoDaLiDa), T\'{o}rshavn, Faroe Islands, May 22nd-24th, 2023. [v2]: added funding acknowledgments