A Survey on Data-driven Software Vulnerability Assessment and Prioritization
arXiv:2107.08364 · doi:10.1145/3529757
Abstract
Software Vulnerabilities (SVs) are increasing in complexity and scale, posing great security risks to many software systems. Given the limited resources in practice, SV assessment and prioritization help practitioners devise optimal SV mitigation plans based on various SV characteristics. The surges in SV data sources and data-driven techniques such as Machine Learning and Deep Learning have taken SV assessment and prioritization to the next level. Our survey provides a taxonomy of the past research efforts and highlights the best practices for data-driven SV assessment and prioritization. We also discuss the current limitations and propose potential solutions to address such issues.
Accepted for publication in the ACM Computing Surveys journal (CSUR), 2022
References in corpus (19)
- Semi-Supervised Classification with Graph Convolutional Networks
- Distributed Representations of Sentences and Documents
- Supervised Topic Models
- VulDeePecker: A Deep Learning-Based System for Multiclass Vulnerability Detection
- Evaluation Metrics for Unsupervised Learning Algorithms
- Predicting Exploitation of Disclosed Software Vulnerabilities Using Open-source Data
- Automated Software Vulnerability Assessment with Concept Drift
- The Impact of a Major Security Event on an Open Source Project: The Case of OpenSSL
- A Survey on Neural Network Interpretability
- Generating Informative CVE Description From ExploitDB Posts by Extractive Summarization
- Classifying Web Exploits with Topic Modeling
- Learning to Catch Security Patches
- Automated Mapping of Vulnerability Advisories onto their Fix Commits in Open Source Repositories
- Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses
- On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
- Predicting Missing Information of Key Aspects in Vulnerability Reports
- V2W-BERT: A Framework for Effective Hierarchical Multiclass Classification of Software Vulnerabilities
- Software Security Patch Management -- A Systematic Literature Review of Challenges, Approaches, Tools and Practices
- Legal Risks of Adversarial Machine Learning Research
Cited by in corpus (4)
- Toward Improved Deep Learning-based Vulnerability Detection
- Automated Code-centric Software Vulnerability Assessment: How Far Are We? An Empirical Study in C/C++
- An Overview of Integration of the Virtualization of Network Functions in the Context of Information Centric Networks
- Automated Security Assessment for the Internet of Things