arXiv:2412.04756cs.CRcs.CL2024-12被引 19

用大模型让漏洞报告更易懂,提升安全评估效率。

ChatNVD: Advancing Cybersecurity Vulnerability Assessment with Large Language Models

  • 用大模型从NVD数据生成通俗易懂的漏洞摘要。
  • GPT-4o Mini准确率达92%以上,错误率最低。
  • 适合安全工程师快速理解复杂漏洞细节。

软件系统中漏洞频发且日益复杂,亟需更有效、更可靠的漏洞评估方法。现有方法多依赖高度技术化和抽象的框架,难以理解且易被利用,导致严重网络攻击。本文提出ChatNVD,一种基于大语言模型(LLM)的辅助工具,利用国家漏洞数据库(NVD)生成上下文丰富、易于理解的漏洞摘要。我们开发了三种变体,分别采用OpenAI的GPT-4o Mini、Meta的LLaMA 3和Google的Gemini 1.5 Pro。通过对比评估其在识别、解释和说明漏洞方面的能力,结果表明GPT-4o Mini表现最优,准确率超过92%,错误率最低,是实际应用中最可靠的选项。

原文摘要 · Abstract (English)

The increasing frequency and sophistication of cybersecurity vulnerabilities in software systems underscores the need for more robust and effective vulnerability assessment methods. However, existing approaches often rely on highly technical and abstract frameworks, which hinder understanding and increase the likelihood of exploitation, resulting in severe cyberattacks. In this paper, we introduce ChatNVD, a support tool powered by Large Language Models (LLMs) that leverages the National Vulnerability Database (NVD) to generate accessible, context-rich summaries of software vulnerabilities. We develop three variants of ChatNVD, utilizing three prominent LLMs: GPT-4o Mini by OpenAI, LLaMA 3 by Meta, and Gemini 1.5 Pro by Google. To evaluate their performance, we conduct a comparative evaluation focused on their ability to identify, interpret, and explain software vulnerabilities. Our results demonstrate that GPT-4o Mini outperforms the other models, achieving over 92% accuracy and the lowest error rates, making it the most reliable option for real-world vulnerability assessment.

漏洞检测大模型安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。