Visible to the public Software Vulnerabilities, Products and Exploits: A Statistical Relational Learning Approach

TitleSoftware Vulnerabilities, Products and Exploits: A Statistical Relational Learning Approach
Publication TypeConference Paper
Year of Publication2021
AuthorsFigueiredo, Cainã, Lopes, João Gabriel, Azevedo, Rodrigo, Zaverucha, Gerson, Menasché, Daniel Sadoc, Pfleger de Aguiar, Leandro
Conference Name2021 IEEE International Conference on Cyber Security and Resilience (CSR)
Keywordscomposability, exploits, feature extraction, Human Behavior, Instruments, integrated circuits, knowledge based systems, Metrics, Pipelines, pubcrawl, relational database security, resilience, Resiliency, security, Software, Statistical relational learning, Weapons
AbstractData on software vulnerabilities, products and exploits is typically collected from multiple non-structured sources. Valuable information, e.g., on which products are affected by which exploits, is conveyed by matching data from those sources, i.e., through their relations. In this paper, we leverage this simple albeit unexplored observation to introduce a statistical relational learning (SRL) approach for the analysis of vulnerabilities, products and exploits. In particular, we focus on the problem of determining the existence of an exploit for a given product, given information about the relations between products and vulnerabilities, and vulnerabilities and exploits, focusing on Industrial Control Systems (ICS), the National Vulnerability Database and ExploitDB. Using RDN-Boost, we were able to reach an AUC ROC of 0.83 and an AUC PR of 0.69 for the problem at hand. To reach that performance, we indicate that it is instrumental to include textual features, e.g., extracted from the description of vulnerabilities, as well as structured information, e.g., about product categories. In addition, using interpretable relational regression trees we report simple rules that shed insight on factors impacting the weaponization of ICS products.
DOI10.1109/CSR51186.2021.9527984
Citation Keyfigueiredo_software_2021