Automated CVE Analysis for Threat Prioritization and Impact Prediction
Ehsan Aghaei, Ehab Al-Shaer, Waseem Shadid, Xi Niu

TL;DR
This paper presents CVEDrill, an automated tool that predicts CVSS scores and classifies CVEs into CWE categories, significantly improving the speed and accuracy of vulnerability analysis for cybersecurity threat prioritization.
Contribution
Introduction of CVEDrill, a novel predictive model and tool that automates CVE analysis, enhancing threat prioritization and impact prediction beyond existing manual and automated methods.
Findings
CVEDrill achieves high accuracy in CVSS vector prediction.
Automates CWE classification for CVEs effectively.
Outperforms state-of-the-art tools like ChatGPT in threat analysis.
Abstract
The Common Vulnerabilities and Exposures (CVE) are pivotal information for proactive cybersecurity measures, including service patching, security hardening, and more. However, CVEs typically offer low-level, product-oriented descriptions of publicly disclosed cybersecurity vulnerabilities, often lacking the essential attack semantic information required for comprehensive weakness characterization and threat impact estimation. This critical insight is essential for CVE prioritization and the identification of potential countermeasures, particularly when dealing with a large number of CVEs. Current industry practices involve manual evaluation of CVEs to assess their attack severities using the Common Vulnerability Scoring System (CVSS) and mapping them to Common Weakness Enumeration (CWE) for potential mitigation identification. Unfortunately, this manual analysis presents a major…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software Engineering Research · Network Security and Intrusion Detection
Methodstravel james
