2020
DOI: 10.1371/journal.pone.0228439
|View full text |Cite
|
Sign up to set email alerts
|

FastEmbed: Predicting vulnerability exploitation possibility based on ensemble machine learning algorithm

Abstract: In recent years, the number of vulnerabilities discovered and publicly disclosed has shown a sharp upward trend. However, the value of exploitation of vulnerabilities varies for attackers, considering that only a small fraction of vulnerabilities are exploited. Therefore, the realization of quick exclusion of the non-exploitable vulnerabilities and optimal patch prioritization on limited resources has become imperative for organizations. Recent works using machine learning techniques predict exploited vulnerab… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
26
0
2

Year Published

2020
2020
2023
2023

Publication Types

Select...
4
3
2

Relationship

0
9

Authors

Journals

citations
Cited by 56 publications
(28 citation statements)
references
References 35 publications
0
26
0
2
Order By: Relevance
“…After the security vulnerabilities are published in the NVD database, the official notification is completed. However, the criticism that the definitions in the reports do not adequately express the relevant weakness is emphasized by the experts in the field [16]. With these criticisms, security vulnerability databases have been published by different organizations due to the problems caused by the institutional structures of CVE and NVD.…”
Section: Related Workmentioning
confidence: 99%
“…After the security vulnerabilities are published in the NVD database, the official notification is completed. However, the criticism that the definitions in the reports do not adequately express the relevant weakness is emphasized by the experts in the field [16]. With these criticisms, security vulnerability databases have been published by different organizations due to the problems caused by the institutional structures of CVE and NVD.…”
Section: Related Workmentioning
confidence: 99%
“…SecurityFocus en önemli ve en saygın güvenlik açığı veri tabanlarından biridir. NVD veri tabanındaki tanımlamalara göre SecurityFocus listelerindeki tanımlamalar güvenlik açığının etkisini ve sömürülebilirliğini daha spesifik olarak açıklamaktadır (Fang et al 2020).…”
Section: Securityfocusunclassified
“…Fang vd. (Fang et al 2020), güvenlik açıklarının sadece küçük bir bölümünün saldırganlar tarafından istismar edildiğini belirtmiştir. Bu nedenle istismar edilemez güvenlik açıkları ile diğerlerinin ayırt edilmesinin sınırlı kaynakların verimli kullanımını sağlayacağını vurgulamaktadır.…”
Section: Introductionunclassified
“…Additionally, a vulnerability prediction system, which was developed based on ensemble machine learning algorithms, employed the FastText model for the encoding task [7]. Given these points, many word embedding techniques had been implemented for detecting vulnerabilities in software code.…”
Section: Related Workmentioning
confidence: 99%