用外部数据自动补全漏洞描述,让安全报告更完整易懂。
Enhancing Vulnerability Reports with Automated and Augmented Description Summarization
- 通过双编码器筛选外部数据,构建详细漏洞语料库
- 在语料库上微调模型,生成更连贯的漏洞描述
- 适合安全研究人员和漏洞管理团队快速理解风险
公开漏洞数据库(如国家漏洞数据库NVD)虽有助于威胁信息共享,但常因描述过短或信息陈旧而难以使用。本文提出Zad系统,利用外部资源增强NVD漏洞描述。Zad包含两条流水线:一条通过双编码器收集并过滤补充数据,构建详实语料库;另一条在此基础上微调预训练模型,生成丰富描述。该方法有效缓解描述简略问题,提升内容质量与连贯性。我们采用标准摘要评估指标与人工评测验证效果,结果表明Zad显著改善了漏洞信息的完整性与可读性。
原文摘要 · Abstract (English)
Public vulnerability databases, such as the National Vulnerability Database (NVD), document vulnerabilities and facilitate threat information sharing. However, they often suffer from short descriptions and outdated or insufficient information. In this paper, we introduce Zad, a system designed to enrich NVD vulnerability descriptions by leveraging external resources. Zad consists of two pipelines: one collects and filters supplementary data using two encoders to build a detailed dataset, while the other fine-tunes a pre-trained model on this dataset to generate enriched descriptions. By addressing brevity and improving content quality, Zad produces more comprehensive and cohesive vulnerability descriptions. We evaluate Zad using standard summarization metrics and human assessments, demonstrating its effectiveness in enhancing vulnerability information.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。