arXiv:2512.15803cs.CRcs.LG2025-12被引 1

分析415个零日漏洞,揭示高危漏洞的特征与预测方法。

An empirical analysis of zero-day vulnerabilities disclosed by the zero day initiative

  • 基于ZDI数据集,结合结构化与文本信息建模
  • 发现漏洞严重性与披露时间、厂商相关性显著
  • 适合安全团队用于漏洞优先级评估

本研究分析2024年1月至4月期间零日倡议(ZDI)披露的415个零日漏洞,涵盖漏洞标识符、CVSS v3.0评分、发布日期及简短描述。主要目标包括识别零日漏洞披露趋势,分析不同厂商的严重性分布,并探究哪些漏洞特征最能预示高严重性。同时,比较经典机器学习与深度学习模型在严重性分类上的表现,使用结构化元数据和非结构化文本描述进行建模。研究结果旨在支持更优的补丁优先级策略、更有效的漏洞管理以及组织对新兴零日威胁的应对能力。

原文摘要 · Abstract (English)

Zero-day vulnerabilities represent some of the most critical threats in cybersecurity, as they correspond to previously unknown flaws in software or hardware that are actively exploited before vendors can develop and deploy patches. During this exposure window, affected systems remain defenseless, making zero-day attacks particularly damaging and difficult to mitigate. This study analyzes the Zero Day Initiative (ZDI) vulnerability disclosures reported between January and April 2024, Cole [2025] comprising a total of 415 vulnerabilities. The dataset includes vulnerability identifiers, Common Vulnerability Scoring System (CVSS) v3.0 scores, publication dates, and short textual descriptions. The primary objectives of this work are to identify trends in zero-day vulnerability disclosures, examine severity distributions across vendors, and investigate which vulnerability characteristics are most indicative of high severity. In addition, this study explores predictive modeling approaches for severity classification, comparing classical machine learning techniques with deep learning models using both structured metadata and unstructured textual descriptions. The findings aim to support improved patch prioritization strategies, more effective vulnerability management, and enhanced organizational preparedness against emerging zero-day threats.

零日漏洞安全分析机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。