English

Structured Extraction of Vulnerabilities in OpenVAS and Tenable WAS Reports Using LLMs

Cryptography and Security 2025-11-21 v1

Abstract

This paper proposes an automated LLM-based method to extract and structure vulnerabilities from OpenVAS and Tenable WAS scanner reports, converting unstructured data into a standardized format for risk management. In an evaluation using a report with 34 vulnerabilities, GPT-4.1 and DeepSeek achieved the highest similarity to the baseline (ROUGE-L greater than 0.7). The method demonstrates feasibility in transforming complex reports into usable datasets, enabling effective prioritization and future anonymization of sensitive data.

Keywords

Cite

@article{arxiv.2511.15745,
  title  = {Structured Extraction of Vulnerabilities in OpenVAS and Tenable WAS Reports Using LLMs},
  author = {Beatriz Machado and Douglas Lautert and Cristhian Kapelinski and Diego Kreutz},
  journal= {arXiv preprint arXiv:2511.15745},
  year   = {2025}
}

Comments

5 pages, 4 tables, 3 figures, submitted to ERRC/WRSeg 2025

R2 v1 2026-07-01T07:45:56.877Z