Tracking Software Security Topics
Phong Minh Vu, Tung Thanh Nguyen

TL;DR
This paper introduces SOSK, a tool that helps stakeholders track and retrieve relevant software security reports by expanding user-defined keywords through embedding similarity, improving real-time security topic monitoring.
Contribution
The paper presents SOSK, a novel keyword expansion and report retrieval tool tailored for real-time tracking of software security topics from reports.
Findings
SOSK effectively expands keywords based on report content.
SOSK retrieves relevant security reports with improved accuracy.
Preliminary evaluation shows promising results in keyword expansion and report retrieval.
Abstract
Software security incidents occur everyday and thousands of software security reports are announced each month. Thus, it is difficult for software security researchers, engineers, and other stakeholders to follow software security topics of their interests in real-time. In this paper, we propose, SOSK, a novel tool for this problem. SOSK allows a user to import a collection of software security reports. It pre-processes and extracts the most important keywords from the textual description of the reports. Based on the similarity of embedding vectors of keywords, SOSK can expand and/or refine a keyword set from a much smaller set of user-provided keywords. Thus, SOSK allows users to define any topic of their interests and retrieve security reports relevant to that topic effectively. Our preliminary evaluation shows that SOSK can expand keywords and retrieve reports relevant to user…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security
MethodsSparse Evolutionary Training
