English

Tracking Software Security Topics

Software Engineering 2024-09-30 v1 Artificial Intelligence Cryptography and Security Information Retrieval

Abstract

Software security incidents occur everyday and thousands of software security reports are announced each month. Thus, it is difficult for software security researchers, engineers, and other stakeholders to follow software security topics of their interests in real-time. In this paper, we propose, SOSK, a novel tool for this problem. SOSK allows a user to import a collection of software security reports. It pre-processes and extracts the most important keywords from the textual description of the reports. Based on the similarity of embedding vectors of keywords, SOSK can expand and/or refine a keyword set from a much smaller set of user-provided keywords. Thus, SOSK allows users to define any topic of their interests and retrieve security reports relevant to that topic effectively. Our preliminary evaluation shows that SOSK can expand keywords and retrieve reports relevant to user requests.

Keywords

Cite

@article{arxiv.2409.18351,
  title  = {Tracking Software Security Topics},
  author = {Phong Minh Vu and Tung Thanh Nguyen},
  journal= {arXiv preprint arXiv:2409.18351},
  year   = {2024}
}