Fetching the paper…
Reading the bibliography…
Software Vulnerabilities (SVs) are increasing in complexity and scale, posing great security risks to many software systems.
Principal component analysis
Svante Wold, Kim Esbensen, and Paul Geladi. 1987 · 1987
Earlier work this paper cites.
Interprocedural slicing using dependence graphs
Susan Horwitz, Thomas Reps, and David Binkley. 1990 · 1990
Earlier work this paper cites.
The self-organizing map
Teuvo Kohonen. 1990 · 1990
Earlier work this paper cites.
Building a large annotated corpus of English: The Penn Treebank
Mitchell Marcus, Beatrice Santorini, and Mary Ann Marcinkiewicz. 1993 · 1993
Earlier work this paper cites.
Support-vector networks
Corinna Cortes and Vladimir Vapnik. 1995 · 1995
Earlier work this paper cites.
Long short-term memory
Sepp Hochreiter and Jürgen Schmidhuber. 1997 · 1997
Earlier work this paper cites.
Mining frequent patterns without candidate generation
Jiawei Han, Jian Pei, and Yiwen Yin. 2000 · 2000
Earlier work this paper cites.
REMUS: A security-enhanced operating system
Massimo Bernaschi, Emanuele Gabrielli, and Luigi V Mancini. 2002 · 2002
Earlier work this paper cites.
Is combining classifiers better than selecting the best one?. In ICML , Vol. 2002. Citeseer, 123e30
Saso Dzeroski and Bernard Zenko. 2002 · 2002
Earlier work this paper cites.
Evolving neural networks through augmenting topologies
Kenneth O Stanley and Risto Miikkulainen. 2002 · 2002
Earlier work this paper cites.
Latent dirichlet allocation
David M Blei, Andrew Y Ng, and Michael I Jordan. 2003 · 2003
Earlier work this paper cites.
Incorporating non-local information into information extraction systems by gibbs sampling. In Proceedings of the 43rd Annual Meeting of the Association for Computational Linguistics (ACL’05) . 363–370
Jenny Rose Finkel, Trond Grenager, and Christopher D Manning. 2005 · 2005
Earlier work this paper cites.
MulVAL: A logic-based network security analyzer. In USENIX security symposium , Vol. 8. Baltimore, MD, 113–128
Xinming Ou, Sudhakar Govindavajhala, and Andrew W Appel. 2005 · 2005
Earlier work this paper cites.
Online passive aggressive algorithms
Koby Crammer, Ofer Dekel, Joseph Keshet, Shai Shalev-Shwartz, and Yoram Singer. 2006 · 2006
Earlier work this paper cites.
Supervised topic models. In Proceedings of the 20th International Conference on Neural Information Processing Systems . 121–128
David M. Blei and Jon D. McAuliffe. 2007 · 2007
Earlier work this paper cites.
Guidelines for performing systematic literature reviews in software engineering
Staffs Keele et al · 2007
Earlier work this paper cites.
Standardising vulnerability categories
Hein S Venter, Jan HP Eloff, and YL Li. 2008 · 2008
Earlier work this paper cites.
The elements of statistical learning: data mining, inference, and prediction
Trevor Hastie, Robert Tibshirani, and Jerome Friedman. 2009 · 2009
Earlier work this paper cites.
A survey on transfer learning
Sinno Jialin Pan and Qiang Yang. 2009 · 2009
Earlier work this paper cites.
Beyond heuristics: learning to classify vulnerabilities and predict exploits. In Proceedings of the 16th ACM SIGKDD international conference on Knowledge discovery and data mining . 105–114
Mehran Bozorgi, Lawrence K Saul, Stefan Savage, and Geoffrey M Voelker. 2010 · 2010
Earlier work this paper cites.
A categorization framework for common computer vulnerabilities and exposures
Zhongqiang Chen, Yuan Zhang, and Zhongrong Chen. 2010 · 2010
Earlier work this paper cites.
Identifying security bug reports via text mining: An industrial case study. In 2010 7th IEEE Working Conference on Mining Software Repositories (MSR 2010) . IEEE, 11–20
Michael Gegick, Pete Rotella, and Tao Xie. 2010 · 2010
Earlier work this paper cites.
Boruta–a system for feature selection
Miron B Kursa, Aleksander Jankowski, and Witold R Rudnicki. 2010 · 2010
Earlier work this paper cites.
An attack surface metric
Pratyusa K Manadhata and Jeannette M Wing. 2010 · 2010
Earlier work this paper cites.
Security trend analysis with cve topic models. In 2010 IEEE 21st International Symposium on Software Reliability Engineering . IEEE, 111–120
Stephan Neuhaus and Thomas Zimmermann. 2010 · 2010
Earlier work this paper cites.
Vulnerability categorization using Bayesian networks. In Proceedings of the sixth annual workshop on cyber security and information intelligence research . 1–4
Ju An Wang and Minzhe Guo. 2010 · 2010
Earlier work this paper cites.
What makes a good bug report?
Thomas Zimmermann, Rahul Premraj, Nicolas Bettenburg, Sascha Just, Adrian Schroter, and Cathrin Weiss. 2010 · 2010
Earlier work this paper cites.
Research synthesis in software engineering: A tertiary study
Daniela S Cruzes and Tore Dybå. 2011 · 2011
Earlier work this paper cites.
Data mining concepts and techniques third edition
Jiawei Han, Micheline Kamber, and Jian Pei. 2011 · 2011
Earlier work this paper cites.
Unleashing mayhem on binary code. In 2012 IEEE Symposium on Security and Privacy . IEEE, 380–394
Sang Kil Cha, Thanassis Avgerinos, Alexandre Rebert, and David Brumley. 2012 · 2012
Earlier work this paper cites.
When a patch goes bad: Exploring the properties of vulnerability-contributing commits. In 2013 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement . IEEE, 65–74
Andrew Meneely, Harshavardhan Srinivasan, Ayemi Musa, Alberto Rodriguez Tejeda, Matthew Mokary, and Brian Spates. 2013 · 2013
Earlier work this paper cites.
Distributed representations of words and phrases and their compositionality
Tomas Mikolov, Ilya Sutskever, Kai Chen, Greg Corrado, and Jeffrey Dean. 2013 · 2013
Earlier work this paper cites.
Automatic classification for vulnerability based on machine learning. In 2013 IEEE International Conference on Information and Automation (ICIA) . IEEE, 312–318
Bo Shuai, Haifeng Li, Mengjun Li, Quan Zhang, and Chaojing Tang. 2013 · 2013
Earlier work this paper cites.
WIVSS: a new methodology for scoring information systems vulnerabilities. In Proceedings of the 17th panhellenic conference on informatics . 83–90
Georgios Spanos, Angeliki Sioziou, and Lefteris Angelis. 2013 · 2013
Earlier work this paper cites.
Predicting bug-fixing time: an empirical study of commercial software projects. In 2013 35th International Conference on Software Engineering (ICSE) . IEEE, 1042–1051
Hongyu Zhang, Liang Gong, and Steve Versteeg. 2013 · 2013
Earlier work this paper cites.
Neural machine translation by jointly learning to align and translate
Dzmitry Bahdanau, Kyunghyun Cho, and Yoshua Bengio. 2014 · 2014
Earlier work this paper cites.
Identifying the characteristics of vulnerable code changes: An empirical study. In Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering . 257–268
Amiangshu Bosu, Jeffrey C Carver, Munawar Hafiz, Patrick Hilley, and Derek Janni. 2014 · 2014
Earlier work this paper cites.
A survey on feature selection methods
Girish Chandrashekar and Ferat Sahin. 2014 · 2014
Earlier work this paper cites.
Convolutional neural networks for sentence classification. In Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing (EMNLP) . Association for Computational Linguistics, 1746–1751
Yoon Kim. 2014 · 2014
Earlier work this paper cites.
Multilayer networks
Mikko Kivelä, Alex Arenas, Marc Barthelemy, James P Gleeson, Yamir Moreno, and Mason A Porter. 2014 · 2014
Earlier work this paper cites.
Distributed representations of sentences and documents. In International conference on machine learning . PMLR, 1188–1196
Quoc Le and Tomas Mikolov. 2014 · 2014
Earlier work this paper cites.
Automated extraction of vulnerability information for home computer security. In International Symposium on Foundations and Practice of Security . Springer, 356–366
Sachini Weerawardhana, Subhojeet Mukherjee, Indrajit Ray, and Adele Howe. 2014 · 2014
Earlier work this paper cites.
Using software structure to predict vulnerability exploitation potential. In 2014 IEEE Eighth International Conference on Software Security and Reliability-Companion . IEEE, 13–18
Awad A Younis and Yashwant K Malaiya. 2014 · 2014
Earlier work this paper cites.
Factors impacting the effort required to fix security vulnerabilities. In International Conference on Information Security . Springer, 102–119
Lotfi ben Othmane, Golriz Chehrazi, Eric Bodden, Petar Tsalovski, Achim D Brucker, and Philip Miseldine. 2015 · 2015
Earlier work this paper cites.
Predicting exploit likelihood for cyber vulnerabilities with machine learning
MICHEL Edkrantz. 2015 · 2015
Earlier work this paper cites.
Predicting vulnerability exploits in the wild. In 2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing . IEEE, 513–514
Michel Edkrantz, Staffan Truvé, and Alan Said. 2015 · 2015
Earlier work this paper cites.
Recurrent convolutional neural networks for text classification. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 29
Siwei Lai, Liheng Xu, Kang Liu, and Jun Zhao. 2015 · 2015
Earlier work this paper cites.
A dataset of high impact bugs: Manually-classified issue reports. In 2015 IEEE/ACM 12th Working Conference on Mining Software Repositories . IEEE, 518–521
Masao Ohira, Yutaro Kashiwa, Yosuke Yamatani, Hayato Yoshiyuki, Yoshiya Maeda, Nachai Limsettho, Keisuke Fujino, Hideaki Hata, Akinori Ihara, and Kenichi Matsumoto. 2015 · 2015
Earlier work this paper cites.
Vulnerability disclosure in the age of social media: Exploiting twitter for predicting real-world exploits. In 24th { \{ USENIX } \} Security Symposium . 1041–1056
Carl Sabottke, Octavian Suciu, and Tudor Dumitra · 2015
Earlier work this paper cites.
A novel automatic severity vulnerability assessment framework
Tao Wen, Yuqing Zhang, Ying Dong, and Gang Yang. 2015 · 2015
Earlier work this paper cites.
Text-mining approach for estimating vulnerability score. In 2015 4th International Workshop on Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS) . IEEE, 67–73
Yasuhiro Yamamoto, Daisuke Miyamoto, and Masaya Nakayama. 2015 · 2015
Earlier work this paper cites.
Character-level convolutional networks for text classification
Xiang Zhang, Junbo Zhao, and Yann LeCun. 2015 · 2015
Earlier work this paper cites.
Aligning books and movies: Towards story-like visual explanations by watching movies and reading books. In Proceedings of the IEEE international conference on computer vision . 19–27
Yukun Zhu, Ryan Kiros, Rich Zemel, Ruslan Salakhutdinov, Raquel Urtasun, Antonio Torralba, and Sanja Fidler. 2015 · 2015
Earlier work this paper cites.
Turning from TF-IDF to TF-IGM for term weighting in text classification
Kewen Chen, Zuping Zhang, Jun Long, and Hao Zhang. 2016 · 2016
Earlier work this paper cites.
Xgboost: A scalable tree boosting system. In Proceedings of the 22nd International Conference on Knowledge Discovery and Data Mining . 785–794
Tianqi Chen and Carlos Guestrin. 2016 · 2016
Earlier work this paper cites.
Lava: Large-scale automated vulnerability addition. In 2016 IEEE Symposium on Security and Privacy (SP) . IEEE, 110–121
Brendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek, Andrea Mambretti, Wil Robertson, Frederick Ulrich, and Ryan Whelan. 2016 · 2016
Earlier work this paper cites.
Deep learning
Ian Goodfellow, Yoshua Bengio, and Aaron Courville. 2016 · 2016
Earlier work this paper cites.
Toward large-scale vulnerability discovery using machine learning. In Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy . 85–96
Gustavo Grieco, Guillermo Luis Grinblat, Lucas Uzal, Sanjay Rawat, Josselin Feist, and Laurent Mounier. 2016 · 2016
Earlier work this paper cites.
Performance measures in evaluating machine learning based bioinformatics predictors for classifications
Yasen Jiao and Pufeng Du. 2016 · 2016
Earlier work this paper cites.
An automatic method for CVSS score prediction using vulnerabilities description
Atefeh Khazaei, Mohammad Ghasemzadeh, and Vali Derhami. 2016 · 2016
Earlier work this paper cites.
Semi-supervised classification with graph convolutional networks
Thomas N Kipf and Max Welling. 2016 · 2016
Earlier work this paper cites.
Mining trends and patterns of software vulnerabilities
Syed Shariyar Murtaza, Wael Khreich, Abdelwahab Hamou-Lhadj, and Ayse Basar Bener. 2016 · 2016
Earlier work this paper cites.
A study on the classification of common vulnerabilities and exposures using naïve bayes. In International Conference on Broadband and Wireless Computing, Communication and Applications . Springer, 657–662
Sarang Na, Taeeun Kim, and Hwankuk Kim. 2016 · 2016
Earlier work this paper cites.
Darknet and deepnet mining for proactive cybersecurity threat intelligence. In 2016 IEEE Conference on Intelligence and Security Informatics (ISI) . IEEE, 7–12
Eric Nunes, Ahmad Diab, Andrew Gunn, Ericsson Marin, Vineet Mishra, Vivin Paliath, John Robertson, Jana Shakarian, Amanda Thart, and Paulo Shakarian. 2016 · 2016
Earlier work this paper cites.
MACKE: Compositional analysis of low-level vulnerabilities with symbolic execution. In Proceedings of the 31st IEEE/ACM International Conference on Automated Software Engineering . 780–785
Saahil Ognawala, Martín Ochoa, Alexander Pretschner, and Tobias Limmer. 2016 · 2016
Earlier work this paper cites.
Associating the Severity of Vulnerabilities with their Description. In International Conference on Advanced Information Systems Engineering . Springer, 231–242
Dimitrios Toloudis, Georgios Spanos, and Lefteris Angelis. 2016 · 2016
Earlier work this paper cites.
Proactive identification of exploits in the wild through vulnerability mentions online. In 2017 International Conference on Cyber Conflict (CyCon US) . IEEE, 82–88
Mohammed Almukaynizi, Eric Nunes, Krishna Dharaiya, Manoj Senguttuvan, Jana Shakarian, and Paulo Shakarian. 2017 · 2017
Earlier work this paper cites.
Enriching word vectors with subword information
Piotr Bojanowski, Edouard Grave, Armand Joulin, and Tomas Mikolov. 2017 · 2017
Earlier work this paper cites.
Predicting exploitation of disclosed software vulnerabilities using open-source data. In Proceedings of the 3rd ACM on International Workshop on Security And Privacy Analytics . 45–53
Benjamin L Bullough, Anna K Yanchenko, Christopher L Smith, and Joseph R Zipkin. 2017 · 2017
Earlier work this paper cites.
Automatic vulnerability classification using machine learning. In International Conference on Risks and Security of Internet and Systems . Springer, 3–17
Marian Gawron, Feng Cheng, and Christoph Meinel. 2017 · 2017
Earlier work this paper cites.
Software vulnerability analysis and discovery using machine-learning and data-mining techniques: A survey
Seyed Mohammad Ghaffarian and Hamid Reza Shahriari. 2017 · 2017
Earlier work this paper cites.
Learning to predict severity of software vulnerability using only vulnerability description. In 2017 IEEE International Conference on Software Maintenance and Evolution (ICSME) . IEEE, 125–136
Zhuobing Han, Xiaohong Li, Zhenchang Xing, Hongtao Liu, and Zhiyong Feng. 2017 · 2017
Earlier work this paper cites.
Lightgbm: A highly efficient gradient boosting decision tree
Guolin Ke, Qi Meng, Thomas Finley, Taifeng Wang, Wei Chen, Weidong Ma, Qiwei Ye, and Tie-Yan Liu. 2017 · 2017
Cited alongside, same era.
Machine learning in vulnerability databases. In 2017 10th International Symposium on Computational Intelligence and Design (ISCID) , Vol. 1. IEEE, 108–113
Zhechao Lin, Xiang Li, and Xiaohui Kuang. 2017 · 2017
Cited alongside, same era.
A scalable model for tracking topical evolution in large document collections. In 2017 IEEE International Conference on Big Data (Big Data) . IEEE, 726–735
Sheikh Motahar Naim, Arnold P Boedihardjo, and M Shahriar Hossain. 2017 · 2017
Cited alongside, same era.
Time for addressing software security issues: Prediction models and impacting factors
Lotfi Ben Othmane, Golriz Chehrazi, Eric Bodden, Petar Tsalovski, and Achim D Brucker. 2017 · 2017
Cited alongside, same era.
Text filtering and ranking for security bug report prediction
Fayola Peters, Thein Than Tun, Yijun Yu, and Bashar Nuseibeh. 2017 · 2017
Is using deep learning frameworks free? characterizing technical debt in deep learning frameworks. In Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering: Software Engineering in Society . 1–10
Jiakun Liu, Qiao Huang, Xin Xia, Emad Shihab, David Lo, and Shanping Li. 2020 · 2020
Later among the works it cites.
The not yet exploited goldmine of OSINT: Opportunities, open challenges and future trends
Javier Pastor-Galindo, Pantaleone Nespoli, Félix Gómez Mármol, and Gregorio Martínez Pérez. 2020 · 2020
Later among the works it cites.
Learning to Catch Security Patches
Arthur D Sawadogo, Tegawendé F Bissyandé, Naouel Moha, Kevin Allix, Jacques Klein, Li Li, and Yves Le Traon. 2020 · 2020
Later among the works it cites.
Literature survey of deep learning-based vulnerability analysis on source code
Abubakar Omari Abdallah Semasaba, Wei Zheng, Xiaoxue Wu, and Samuel Akwasi Agyemang. 2020 · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Classifying web exploits with topic modeling. In 2017 28th International Workshop on Database and Expert Systems Applications (DEXA) . IEEE, 93–97
Jukka Ruohonen. 2017 · 2017
Cited alongside, same era.
Software vulnerability management: how intelligence helps reduce the risk
Vincent Smyth. 2017 · 2017
Cited alongside, same era.
Assessment of vulnerability severity using text mining. In Proceedings of the 21st Pan-Hellenic Conference on Informatics . 1–6
Georgios Spanos, Lefteris Angelis, and Dimitrios Toloudis. 2017 · 2017
Cited alongside, same era.
Exniffer: Learning to prioritize crashes by assessing the exploitability from memory dump. In 2017 24th Asia-Pacific Software Engineering Conference (APSEC) . IEEE, 239–248
Shubham Tripathi, Gustavo Grieco, and Sanjay Rawat. 2017 · 2017
Cited alongside, same era.
Exploitmeter: Combining fuzzing with machine learning for automated evaluation of software exploitability. In 2017 IEEE Symposium on Privacy-Aware Computing (PAC) . IEEE, 164–175
Guanhua Yan, Junchen Lu, Zhan Shu, and Yunus Kucuk. 2017 · 2017
Cited alongside, same era.
Predicting bug-fixing time: A replication study using an open source software project
Shirin Akbarinasaji, Bora Caglayan, and Ayse Bener. 2018 · 2018
Cited alongside, same era.
Automated generation of attack graphs using nvd. In Proceedings of the 8th Conference on Data and Application Security and Privacy . 135–142
M Ugur Aksu, Kemal Bicakci, M Hadi Dilek, A Murat Ozbayoglu, and E ıslam Tatli. 2018 · 2018
Cited alongside, same era.
Prasha Shrestha, Arun Sathanur, Suraj Maharjan, Emily Saldanha, Dustin Arendt, and Svitlana Volkova. 2020 · 2020
Later among the works it cites.
Applying deep learning for discovery and analysis of software vulnerabilities: A brief survey
Shashank Kumar Singh and Amrita Chaturvedi. 2020 · 2020
Later among the works it cites.
A survey on semi-supervised learning
Jesper E Van Engelen and Holger H Hoos. 2020 · 2020
Later among the works it cites.
Topic modeling and classification of Common Vulnerabilities And Exposures database. In 2020 International Conference on Artificial Intelligence, Big Data, Computing and Data Communication Systems (icABCD) . IEEE, 1–5
Mounika Vanamala, Xiaohong Yuan, and Kaushik Roy. 2020 · 2020
Later among the works it cites.
The impact of a major security event on an open source project: The case of OpenSSL. In Proceedings of the 17th International Conference on Mining Software Repositories . 409–419
James Walden. 2020 · 2020
Later among the works it cites.
Generalizing from a few examples: A survey on few-shot learning
Yaqing Wang, Quanming Yao, James T Kwok, and Lionel M Ni. 2020 · 2020
Later among the works it cites.
Automated CPE labeling of CVE summaries with machine learning. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment . Springer, 3–22
Emil Wåreus and Martin Hell. 2020 · 2020
Later among the works it cites.
Evaluating explanation methods for deep learning in security. In 2020 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 158–174
Alexander Warnecke, Daniel Arp, Christian Wressnegger, and Konrad Rieck. 2020 · 2020
Later among the works it cites.
A vulnerability analysis and prediction framework
Mark A Williams, Roberto Camacho Barranco, Sheikh Motahar Naim, Sumi Dey, M Shahriar Hossain, and Monika Akbar. 2020 · 2020
Later among the works it cites.
Apply transfer learning to cybersecurity: Predicting exploitability of vulnerabilities by description
Jiao Yin, MingJian Tang, Jinli Cao, and Hua Wang. 2020 · 2020
Later among the works it cites.
Software vulnerability analysis and discovery using deep learning techniques: A survey
Peng Zeng, Guanjun Lin, Lei Pan, Yonghang Tai, and Jun Zhang. 2020 · 2020
Later among the works it cites.
A general framework to understand vulnerabilities in information systems
Xiong Zhang, Haoran Xie, Hao Yang, Hongkai Shao, and Minghao Zhu. 2020b · 2020
Later among the works it cites.
A survey on neural network interpretability
Yu Zhang, Peter Tiňo, Aleš Leonardis, and Ke Tang. 2020a · 2020
Later among the works it cites.
Exploitability prediction of software vulnerabilities
Navneet Bhatt, Adarsh Anand, and VSS Yadavalli. 2021 · 2021
Closest in time.
Security Bug Report Usage for Software Vulnerability Research: A Systematic Mapping Study
Farzana Ahamed Bhuiyan, Md Bulbul Sharif, and Akond Rahman. 2021 · 2021
Closest in time.
A Framework for Modeling Cyber Attack Techniques from Security Vulnerability Descriptions. In Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining . 2574–2583
Hodaya Binyamini, Ron Bitton, Masaki Inokuchi, Tomohiko Yagyu, Yuval Elovici, and Asaf Shabtai. 2021 · 2021
Closest in time.
Siddhartha Shankar Das, Edoardo Serra, Mahantesh Halappanavar, Alex Pothen, and Ehab Al-Shaer. 2021 · 2021
Closest in time.
Automated Security Assessment for the Internet of Things. In 2021 IEEE 26th Pacific Rim International Symposium on Dependable Computing (PRDC) . IEEE, 47–56
Xuanyu Duan, Mengmeng Ge, Triet Huynh Minh Le, Faheem Ullah, Shang Gao, Xuequan Lu, and M Ali Babar. 2021 · 2021
Closest in time.
Automated mapping of vulnerability advisories onto their fix commits in open source repositories
Daan Hommersom, Antonino Sabetta, Bonaventura Coppola, and Damian A Tamburri. 2021 · 2021
Closest in time.
Robustness of on-device models: Adversarial attack to deep learning models on android apps. In 2021 IEEE/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP) . IEEE, 101–110
Yujin Huang, Han Hu, and Chunyang Chen. 2021 · 2021
Closest in time.
Tracing CAPEC attack patterns from CVE vulnerability information using natural language processing technique. In Proceedings of the 54th Hawaii International Conference on System Sciences . 6996
Kenta Kanakogi, Hironori Washizaki, Yoshiaki Fukazawa, Shinpei Ogata, Takao Okubo, Takehisa Kato, Hideyuki Kanuka, Atsuo Hazeyama, and Nobukazu Yoshioka. 2021 · 2021
Closest in time.
Deepcva: Automated commit-level vulnerability assessment with deep multi-task learning. In 2021 36th IEEE/ACM International Conference on Automated Software Engineering (ASE) . IEEE, 717–729
Triet HM Le, David Hin, Roland Croft, and M Ali Babar. 2021b · 2021
Closest in time.
Vulnerability detection with fine-grained interpretations. In Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering
Yi Li, Shaohua Wang, and Tien N Nguyen. 2021 · 2021
Closest in time.
Severity Prediction of Software Vulnerabilities Using Textual Data. In Proceedings of International Conference on Recent Trends in Machine Learning, IoT, Smart Cities and Applications . Springer, 453–464
Ruchika Malhotra et al · 2021
Closest in time.
Shallow or deep? An empirical study on detecting vulnerabilities using deep learning. In Proceedings of the 2021 IEEE/ACM 29th International Conference on Program Comprehension (ICPC) . 276–287
A. Mazuera-Rozo, A. Mojica-Hanke, M. Linares-Vasquez, and G. Bavota. 2021 · 2021
Closest in time.
Adversarial machine learning attacks and defense methods in the cyber security domain
Ishai Rosenberg, Asaf Shabtai, Yuval Elovici, and Lior Rokach. 2021 · 2021
Closest in time.
Machine Learning for Detecting Data Exfiltration: A Review
Bushra Sabir, Faheem Ullah, M Ali Babar, and Raj Gaire. 2021 · 2021
Closest in time.
Software vulnerability prioritization using vulnerability description
Ruchi Sharma, Ritu Sibal, and Sangeeta Sabharwal. 2021 · 2021
Closest in time.
Time to change the CVSS?
Jonathan Spring, Eric Hatleback, Allen Householder, Art Manion, and Deana Shick. 2021 · 2021
Closest in time.
Expected exploitability: Predicting the development of functional vulnerability exploits
Octavian Suciu, Connor Nelson, Zhuoer Lyu, Tiffany Bao, and Tudor Dumitras. 2021 · 2021
Closest in time.
Generating informative CVE description from ExploitDB posts by extractive summarization
Jiamou Sun, Zhenchang Xing, Hao Guo, Deheng Ye, Xiaohong Li, Xiwei Xu, and Liming Zhu. 2021 · 2021
Closest in time.
Data quality matters: A case study on data label correctness for security bug report prediction
Xiaoxue Wu, Wei Zheng, Xin Xia, and David Lo. 2021 · 2021
Closest in time.
Automatic part-of-speech tagging for security vulnerability descriptions. In 2021 IEEE/ACM 18th International Conference on Mining Software Repositories (MSR) . IEEE, 29–40
Sofonias Yitagesu, Xiaowang Zhang, Zhiyong Feng, Xiaohong Li, and Zhenchang Xing. 2021 · 2021
Closest in time.
A survey on multi-task learning
Yu Zhang and Qiang Yang. 2021 · 2021
Closest in time.
Interpreting deep learning-based vulnerability detector predictions based on heuristic searching
Deqing Zou, Yawei Zhu, Shouhuai Xu, Zhen Li, Hai Jin, and Hengkai Ye. 2021 · 2021
Closest in time.
Symantec attack signatures
Broadcom. [n. d.]a · 2022
Closest in time.
Symantec threat explorer
Broadcom. [n. d.]b · 2022
Closest in time.
Basic fuzzing framework
CERT. [n. d.] · 2022
Closest in time.
ESET security advisories
ESET. [n. d.] · 2022
Closest in time.
Common Vulnerability Scoring System
FIRST. [n. d.]a · 2022
Closest in time.
CVSS version 2
FIRST. [n. d.]b · 2022
Closest in time.
CVSS version 3
FIRST. [n. d.]c · 2022
Closest in time.
CVSS version 3.1
FIRST. [n. d.]d · 2022
Closest in time.
Wikipedia pages
Wikimedia Foundation. [n. d.] · 2022
Closest in time.
Recorded Future security advisories
Recorded Future. [n. d.] · 2022
Closest in time.
BugTraq vulnerability database
SecurityFocus Inc. [n. d.] · 2022
Closest in time.
Secunia vulnerability advisories
Secunia Inc. [n. d.] · 2022
Closest in time.
Kenna Security
Inc. Kenna Security. [n. d.] · 2022
Closest in time.
On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
Triet HM Le and M Ali Babar. 2022 · 2022
Closest in time.
Supplementary materials
Triet HM Le, Huaming Chen, and M Ali Babar. [n. d.] · 2022
Closest in time.
Trend Micro security advisories
Trend Micro. [n. d.]a · 2022
Closest in time.
ZeroDay Initiative security advisories
Trend Micro. [n. d.]b · 2022
Closest in time.
Microsoft security advisories
Microsoft. [n. d.] · 2022
Closest in time.
Common Attack Pattern Enumeration and Classification
MITRE. [n. d.]a · 2022
Closest in time.
Common Platform Enumeration
MITRE. [n. d.]b · 2022
Closest in time.
Common Vulnerabilities and Exposures
MITRE. [n. d.]c · 2022
Closest in time.
Common Weakness Enumeration
MITRE. [n. d.]d · 2022
Closest in time.
National Vulnerability Database
NIST. [n. d.]a · 2022
Closest in time.
Software Assurance Reference Dataset (SARD)
NIST. [n. d.]b · 2022
Closest in time.
Vulnerability description ontology
NIST. [n. d.]c · 2022
Closest in time.
Open Web Application Security Project
OWASP. [n. d.] · 2022
Closest in time.
Openwall security advisories
Openwall Project. [n. d.] · 2022
Closest in time.
Metasploit security advisories
Rapid7. [n. d.] · 2022
Closest in time.
Exploit Database
Offensive Security. [n. d.] · 2022
Closest in time.
SecurityTracker vulnerability database
SecurityTracker. [n. d.] · 2022
Closest in time.
Online database X-Force
Internet Security Services. [n. d.] · 2022
Closest in time.
CVE Details
Serkan Özkan. [n. d.] · 2022
Closest in time.
Assisting vulnerability detection by prioritizing crashes with incremental learning. In TENCON 2018-2018 IEEE Region 10 Conference . IEEE, 2080–2085
Li Zhang and Vrizlynn LL Thing. 2018 · 2085
Closest in time.