使用 LLM 从 OpenVAS 和 Tenable WAS 报告中结构化提取漏洞
密码学与安全
2025-11-21 v1
摘要
本文提出一种基于 LLM 的自动方法,用于从 OpenVAS 和 Tenable WAS 扫描器报告中提取并结构化漏洞,将非结构化数据转换为用于风险管理的标准格式。在一次评估中,使用包含 34 项漏洞的报告,GPT-4.1 和 DeepSeek 实现了最高的与基准相似度(ROUGE-L 大于 0.7)。该方法展示了在将复杂报告转换为可用数据集方面的可行性,使有效的优先级排序和未来敏感数据匿名化成为可能。
引用
@article{arxiv.2511.15745,
title = {Structured Extraction of Vulnerabilities in OpenVAS and Tenable WAS Reports Using LLMs},
author = {Beatriz Machado and Douglas Lautert and Cristhian Kapelinski and Diego Kreutz},
journal= {arXiv preprint arXiv:2511.15745},
year = {2025}
}
备注
5 pages, 4 tables, 3 figures, submitted to ERRC/WRSeg 2025