Uncovering product vulnerabilities with threat knowledge graphs

Files
secdev22-final.pdf(341.84 KB)
Accepted manuscript
Date
2022-10
Authors
Shi, Zhenpeng
Matyunin, Nikolay
Graffi, Kalman
Starobinski, David
Version
Accepted manuscript
OA Version
Citation
Z. Shi, N. Matyunin, K. Graffi, D. Starobinski. 2022. "Uncovering Product Vulnerabilities with Threat Knowledge Graphs" 2022 IEEE Secure Development Conference (SecDev), pp.84-90. https://doi.org/10.1109/secdev53368.2022.00028
Abstract
Threat modeling and security assessment rely on public information on products, vulnerabilities and weaknesses. So far, databases in these categories have rarely been analyzed in combination. Yet, doing so could help predict unreported vulnerabilities and identify common threat patterns. In this paper, we propose a methodology for producing and optimizing a knowledge graph that aggregates knowledge from common threat databases (CPE, CVE, and CWE). We apply the threat knowledge graph to predict associations between threat databases, specifically between products and vulnerabilities. We evaluate the prediction performance based on historical data, using precision, recall, and F1-score metrics. We demonstrate the ability of the threat knowledge graph to uncover many associations that are currently unknown but will be revealed in the future.
Description
License