ThreatLinker:一种基于 NLP 的方法,用于自动估计 CVE 与 CAPEC 攻击模式的相关性
密码学与安全
2026-01-13 v2
摘要
威胁分析正因不断增加的复杂性和频率而变得越来越重要。分析威胁需要来自安全专家的大量工作:不同的网络安全知识库支持这一任务,但需要手动 effort 来将异构来源关联成统一视图,以实现更全面的评估。为填补这一差距,我们提出了 ThreatLinker,一种利用自然语言处理(NLP)的方法,有效且高效地将 Common Vulnerabilities and Exposure(CVE)漏洞与 Common Attack Pattern Enumeration and Classification(CAPEC)攻击模式关联起来。所提出的技术结合了语义相似性和关键词分析,以提高关联估计的准确性。我们贡献了一个更大的数据集用于 CVE-CAPEC 相关性,实验评估表明其性能优于现有方法。
引用
@article{arxiv.2501.07131,
title = {ThreatLinker: An NLP-based Methodology to Automatically Estimate CVE Relevance for CAPEC Attack Patterns},
author = {Andrea Ciavotta and Alessandro Palma and Simone Lenti and Silvia Bonomi},
journal= {arXiv preprint arXiv:2501.07131},
year = {2026}
}
备注
8 pages. The paper has been accepted at the 21st European Dependable Computing Conference (EDCC 2026)