CHRONOS: Time-Aware Zero-Shot Identification of Libraries from Vulnerability Reports
Yunbo Lyu, Thanh Le-Cong, Hong Jin Kang, Ratnadira Widyasari, Zhipeng, Zhao, Xuan-Bach D. Le, Ming Li, David Lo

TL;DR
CHRONOS is a time-aware zero-shot learning approach for identifying libraries from vulnerability reports, addressing the limitations of previous methods by considering chronological order and data enrichment to improve real-world applicability.
Contribution
The paper introduces CHRONOS, a novel zero-shot learning method that incorporates temporal information and data enhancement for more accurate library identification from vulnerability reports.
Findings
Performance drops significantly when ignoring chronological order.
CHRONOS outperforms existing XML techniques in realistic, time-aware settings.
Enriching vulnerability data improves library identification accuracy.
Abstract
Tools that alert developers about library vulnerabilities depend on accurate, up-to-date vulnerability databases which are maintained by security researchers. These databases record the libraries related to each vulnerability. However, the vulnerability reports may not explicitly list every library and human analysis is required to determine all the relevant libraries. Human analysis may be slow and expensive, which motivates the need for automated approaches. Researchers and practitioners have proposed to automatically identify libraries from vulnerability reports using extreme multi-label learning (XML). While state-of-the-art XML techniques showed promising performance, their experiment settings do not practically fit what happens in reality. Previous studies randomly split the vulnerability reports data for training and testing their models without considering the chronological…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsWeb Application Security Vulnerabilities · Advanced Malware Detection Techniques · Spam and Phishing Detection
