Skip to main navigation Skip to search Skip to main content

Categorizing and Predicting Invalid Vulnerabilities on Common Vulnerabilities and Exposures

  • Qiuyuan Chen
  • , Lingfeng Bao
  • , Li Li
  • , Xin Xia
  • , Liang Cai
  • Zhejiang University
  • Zhejiang University City College
  • Monash University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

To share vulnerability information across separate databases, tools, and services, newly identified vulnerabilities are recurrently reported to Common Vulnerabilities and Exposures (CVE) database.Unfortunately, not all vulnerability reports will be accepted. Some of them might get rejected or be accepted with disputations.In this work, we refer to those rejected or disputed CVEs as invalid vulnerability reports. Invalid vulnerability reports not only cause unnecessary efforts to confirm the vulnerability but also impact the reputation of the software vendors. In this paper, we aim to understand the root causes of invalid vulnerability reports and build a prediction model to automatically identify them.To this end, we first leverage card sorting to categorize invalid vulnerability reports, from which six main reasons are observed for rejected and disputed CVEs, respectively.Then, we propose a text mining approach to predict the invalid vulnerability reports. Our experiments reveal that the proposed text mining approach can achieve an AUC score of 0.87 for predicting invalid vulnerabilities. We also discuss the implications of our study: our categorization can be used to guide new committer to avoid these traps; some root causes of invalid CVEs can be avoided by using automatic techniques or optimizing reviewing mechanism; invalid vulnerability reports data should not be neglected.

Original languageEnglish
Title of host publicationProceedings - 25th Asia-Pacific Software Engineering Conference, APSEC 2018
PublisherIEEE Computer Society
Pages345-354
Number of pages10
ISBN (Electronic)9781728119700
DOIs
StatePublished - 2 Jul 2018
Externally publishedYes
Event25th Asia-Pacific Software Engineering Conference, APSEC 2018 - Nara, Japan
Duration: 4 Dec 20187 Dec 2018

Publication series

NameProceedings - Asia-Pacific Software Engineering Conference, APSEC
Volume2018-December
ISSN (Print)1530-1362

Conference

Conference25th Asia-Pacific Software Engineering Conference, APSEC 2018
Country/TerritoryJapan
CityNara
Period4/12/187/12/18

Keywords

  • invalid CVE
  • prediction model
  • reason categorization

Fingerprint

Dive into the research topics of 'Categorizing and Predicting Invalid Vulnerabilities on Common Vulnerabilities and Exposures'. Together they form a unique fingerprint.

Cite this