arXiv:2409.18351cs.SEcs.AI2024-09

用关键词自动追踪软件安全事件,快速找到相关报告。

Tracking Software Security Topics

  • 基于关键词嵌入相似性,自动扩展用户输入的关键词集。
  • 能有效检索与用户关注主题相关的安全报告。
  • 适合安全研究人员、工程师实时追踪热点漏洞。

软件安全事件每天都在发生,每月有数千份安全报告发布,使研究人员、工程师及其他利益相关者难以实时跟踪感兴趣的安全话题。本文提出 SOSK,一种新型工具,允许用户导入一组软件安全报告,预处理并从报告文本中提取关键信息。通过关键词嵌入向量的相似性,SOSK 可以从用户提供的少量关键词出发,自动扩展或优化关键词集合,从而实现对任意兴趣主题的有效报告检索。初步评估表明,SOSK 能够成功扩展关键词并准确检索出相关报告。

原文摘要 · Abstract (English)

Software security incidents occur everyday and thousands of software security reports are announced each month. Thus, it is difficult for software security researchers, engineers, and other stakeholders to follow software security topics of their interests in real-time. In this paper, we propose, SOSK, a novel tool for this problem. SOSK allows a user to import a collection of software security reports. It pre-processes and extracts the most important keywords from the textual description of the reports. Based on the similarity of embedding vectors of keywords, SOSK can expand and/or refine a keyword set from a much smaller set of user-provided keywords. Thus, SOSK allows users to define any topic of their interests and retrieve security reports relevant to that topic effectively. Our preliminary evaluation shows that SOSK can expand keywords and retrieve reports relevant to user requests.

软件安全关键词扩展信息检索

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。