Abstract
Cybercriminals relentlessly pursue vulnerabilities across cyberspace to exploit software, threatening the security of individuals, organizations, and governments. Although security teams strive to establish defense measures to thwart attackers, the complexity of cyber defense and the magnitude of existing threats exceed the capacity of defenders. Therefore, MITRE took the initiative and introduced multiple frameworks to facilitate the sharing of vital knowledge about vulnerabilities, attacks, and defense information. The Common Vulnerabilities and Exposures (CVE) program and ATT&CK Matrix are two significant MITRE endeavors. CVE facilitates the sharing of publicly discovered vulnerabilities, while ATT&CK collects and categorizes adversaries’ Tactics, Techniques, and Procedures (TTP) and recommends appropriate countermeasures. As CVE yields a low-level description of the vulnerability, ATT&CK can complement it by providing more insights into that vulnerability from an attacking perspective, thereby aiding defenders in countering exploitation attempts. Unfortunately, due to the complexity of this mapping and the rapid growth of these frameworks, mapping CVE to ATT&CK is a daunting and time-intensive undertaking. Multiple studies have proposed models that automatically achieve this mapping. However, due to their reliance on annotated datasets, these models exhibit limitations in quality and coverage and fail to justify their decisions. To overcome these challenges, we present SMET—a tool that automatically maps CVE entries to ATT&CK techniques based on their textual similarity. SMET achieves this mapping by leveraging ATT&CK BERT, a model that we trained using the SIAMESE network to learn semantic similarity among attack actions. In inference, SMET utilizes semantic extraction, ATT&CK BERT, and a logistic regression model to map CVE entries to ATT&CK techniques. As a result, SMET has demonstrated superior performance compared to other state-of-the-art models.
| Original language | English |
|---|---|
| Title of host publication | Data and Applications Security and Privacy XXXVII - 37th Annual IFIP WG 11.3 Conference, DBSec 2023, Proceedings |
| Editors | Vijayalakshmi Atluri, Anna Lisa Ferrara |
| Publisher | Springer Science and Business Media Deutschland GmbH |
| Pages | 243-260 |
| Number of pages | 18 |
| ISBN (Print) | 9783031375859 |
| DOIs | |
| State | Published - 2023 |
| Externally published | Yes |
| Event | 37th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, DBSec 2023 - Sophia Antipolis, France Duration: 19 Jul 2023 → 21 Jul 2023 |
Publication series
| Name | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) |
|---|---|
| Volume | 13942 LNCS |
| ISSN (Print) | 0302-9743 |
| ISSN (Electronic) | 1611-3349 |
Conference
| Conference | 37th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy, DBSec 2023 |
|---|---|
| Country/Territory | France |
| City | Sophia Antipolis |
| Period | 19/07/23 → 21/07/23 |
Bibliographical note
Publisher Copyright:© 2023, IFIP International Federation for Information Processing.
ASJC Scopus subject areas
- Theoretical Computer Science
- General Computer Science
Fingerprint
Dive into the research topics of 'SMET: Semantic Mapping of CVE to ATT&CK and Its Application to Cybersecurity'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver