Do Chase Your Tail! Missing Key Aspects Augmentation in Textual Vulnerability Descriptions of Long-tail Software through Feature Inference
Linyi Han, Shidong Pan, Zhenchang Xing, Jiamou Sun, Sofonias Yitagesu,, Xiaowang Zhang, Zhiyong Feng

TL;DR
This paper presents a novel framework that leverages cross-referencing, large language models, and classification techniques to augment missing key aspects in textual vulnerability descriptions of long-tail software, improving vulnerability analysis.
Contribution
It introduces a comprehensive feature inference framework combining cross-referencing, LLMs, clustering, NLI models, and wiki explanations to address challenges in long-tail software vulnerability descriptions.
Findings
Effective augmentation of missing key aspects in TVDs for long-tail software.
Improved accuracy in vulnerability description analysis using NLI models.
Enhanced understanding of proprietary terms through wiki explanations.
Abstract
Augmenting missing key aspects in Textual Vulnerability Descriptions (TVDs) is crucial for effective vulnerability analysis. For instance, in TVDs, key aspects include Attack Vector, Vulnerability Type, among others. These key aspects help security engineers understand and address the vulnerability in a timely manner. For software with a large user base (non-long-tail software), augmenting these missing key aspects has significantly advanced vulnerability analysis and software security research. However, software instances with a limited user base (long-tail software) often get overlooked due to inconsistency software names, TVD limited avaliability, and domain-specific jargon, which complicates vulnerability analysis and software repairs. In this paper, we introduce a novel software feature inference framework designed to augment the missing key aspects of TVDs for long-tail software.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSoftware Reliability and Analysis Research · Web Application Security Vulnerabilities · Software Engineering Research
