arXiv:2505.13895cs.CRcs.DB2025-05被引 1

解决漏洞管理中配置识别不准问题,提升安全防护精准度。

VulCPE: Context-Aware Cybersecurity Vulnerability Retrieval and Management

  • 构建统一CPE schema,融合实体识别与关系抽取,建模配置依赖关系。
  • 在真实数据上实现0.766的检索精确率和0.926的覆盖率达行业领先。
  • 适合需要高精度漏洞管理的系统管理员与安全团队使用。

网络安全环境动态变化,异构系统中的漏洞管理面临挑战,因配置相关漏洞常因国家漏洞数据库(NVD)数据不一致而误判。NVD中常见的通用平台枚举(CPE)数据不准确导致大量误报和遗漏。基于对CPE与CVE数据的系统分析,发现超过50%的厂商名称存在不一致问题。为此提出VulCPE框架,通过统一CPE模式(uCPE)、实体识别、关系抽取与图模型,标准化数据并建模配置依赖。实验表明,VulCPE在检索精确率(0.766)和覆盖度(0.926)上优于现有工具,实现更精准、上下文感知的漏洞管理,显著增强网络弹性。

原文摘要 · Abstract (English)

The dynamic landscape of cybersecurity demands precise and scalable solutions for vulnerability management in heterogeneous systems, where configuration-specific vulnerabilities are often misidentified due to inconsistent data in databases like the National Vulnerability Database (NVD). Inaccurate Common Platform Enumeration (CPE) data in NVD further leads to false positives and incomplete vulnerability retrieval. Informed by our systematic analysis of CPE and CVEdeails data, revealing more than 50% vendor name inconsistencies, we propose VulCPE, a framework that standardizes data and models configuration dependencies using a unified CPE schema (uCPE), entity recognition, relation extraction, and graph-based modeling. VulCPE achieves superior retrieval precision (0.766) and coverage (0.926) over existing tools. VulCPE ensures precise, context-aware vulnerability management, enhancing cyber resilience.

漏洞管理CPE安全增强

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。