中文

ThreatLinker:一种基于 NLP 的方法,用于自动估计 CVE 与 CAPEC 攻击模式的相关性

密码学与安全 2026-01-13 v2

摘要

威胁分析正因不断增加的复杂性和频率而变得越来越重要。分析威胁需要来自安全专家的大量工作:不同的网络安全知识库支持这一任务,但需要手动 effort 来将异构来源关联成统一视图,以实现更全面的评估。为填补这一差距,我们提出了 ThreatLinker,一种利用自然语言处理(NLP)的方法,有效且高效地将 Common Vulnerabilities and Exposure(CVE)漏洞与 Common Attack Pattern Enumeration and Classification(CAPEC)攻击模式关联起来。所提出的技术结合了语义相似性和关键词分析,以提高关联估计的准确性。我们贡献了一个更大的数据集用于 CVE-CAPEC 相关性,实验评估表明其性能优于现有方法。

关键词

引用

@article{arxiv.2501.07131,
  title  = {ThreatLinker: An NLP-based Methodology to Automatically Estimate CVE Relevance for CAPEC Attack Patterns},
  author = {Andrea Ciavotta and Alessandro Palma and Simone Lenti and Silvia Bonomi},
  journal= {arXiv preprint arXiv:2501.07131},
  year   = {2026}
}

备注

8 pages. The paper has been accepted at the 21st European Dependable Computing Conference (EDCC 2026)