Skip to main navigation Skip to search Skip to main content

SMET: Semantic Mapping of CVE to ATT&CK and Its Application to Cybersecurity

  • Basel Abdeen*
  • , Ehab Al-Shaer
  • , Anoop Singhal
  • , Latifur Khan
  • , Kevin Hamlen
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

38 Scopus citations

Abstract

Cybercriminals relentlessly pursue vulnerabilities across cyberspace to exploit software, threatening the security of individuals, organizations, and governments. Although security teams strive to establish defense measures to thwart attackers, the complexity of cyber defense and the magnitude of existing threats exceed the capacity of defenders. Therefore, MITRE took the initiative and introduced multiple frameworks to facilitate the sharing of vital knowledge about vulnerabilities, attacks, and defense information. The Common Vulnerabilities and Exposures (CVE) program and ATT&CK Matrix are two significant MITRE endeavors. CVE facilitates the sharing of publicly discovered vulnerabilities, while ATT&CK collects and categorizes adversaries’ Tactics, Techniques, and Procedures (TTP) and recommends appropriate countermeasures. As CVE yields a low-level description of the vulnerability, ATT&CK can complement it by providing more insights into that vulnerability from an attacking perspective, thereby aiding defenders in countering exploitation attempts. Unfortunately, due to the complexity of this mapping and the rapid growth of these frameworks, mapping CVE to ATT&CK is a daunting and time-intensive undertaking. Multiple studies have proposed models that automatically achieve this mapping. However, due to their reliance on annotated datasets, these models exhibit limitations in quality and coverage and fail to justify their decisions. To overcome these challenges, we present SMET—a tool that automatically maps CVE entries to ATT&CK techniques based on their textual similarity. SMET achieves this mapping by leveraging ATT&CK BERT, a model that we trained using the SIAMESE network to learn semantic similarity among attack actions. In inference, SMET utilizes semantic extraction, ATT&CK BERT, and a logistic regression model to map CVE entries to ATT&CK techniques. As a result, SMET has demonstrated superior performance compared to other state-of-the-art models.

Original languageEnglish
Title of host publicationData and Applications Security and Privacy XXXVII - 37th Annual IFIP WG 11.3 Conference, DBSec 2023, Proceedings
EditorsVijayalakshmi Atluri, Anna Lisa Ferrara
PublisherSpringer Science and Business Media Deutschland GmbH
Pages243-260
Number of pages18
ISBN (Print)9783031375859
DOIs
StatePublished - 2023
Externally publishedYes
Event37th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, DBSec 2023 - Sophia Antipolis, France
Duration: 19 Jul 202321 Jul 2023

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13942 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference37th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, DBSec 2023
Country/TerritoryFrance
CitySophia Antipolis
Period19/07/2321/07/23

Bibliographical note

Publisher Copyright:
© 2023, IFIP International Federation for Information Processing.

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Fingerprint

Dive into the research topics of 'SMET: Semantic Mapping of CVE to ATT&CK and Its Application to Cybersecurity'. Together they form a unique fingerprint.

Cite this