• Home
  • Search
  • Enhancing Vulnerability Reports With Automated and Augmented Description Summarization
  • https://doi.org/10.1109/tbdata.2025.3566618Copy DOI Icon

Enhancing Vulnerability Reports With Automated and Augmented Description Summarization

Show More
  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

Public vulnerability databases, such as the National Vulnerability Database (NVD), document vulnerabilities and facilitate threat information sharing. However, they often suffer from short descriptions and outdated or insufficient information. In this paper, we introduce <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">Zad</i>, a system designed to enrich NVD vulnerability descriptions by leveraging external resources. <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">Zad</i> consists of two pipelines: one collects and filters supplementary data using two encoders to build a detailed dataset, while the other fine-tunes a pre-trained model on this dataset to generate enriched descriptions. By addressing brevity and improving content quality, <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">Zad</i> produces more comprehensive and cohesive vulnerability descriptions. We evaluate <italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">Zad</i> using standard summarization metrics and human assessments, demonstrating its effectiveness in enhancing vulnerability information.

Similar Papers
  • Conference Article
  • Citations14

Predictive vulnerability scoring in the context of insufficient information availability

  • Oct 01, 2013
  • Hamza Ghani +4
  • Book Chapter
  • Citations2

Is This IoT Device Likely to Be Secure? Risk Score Prediction for IoT Devices Using Gradient Boosting Machines

  • Jan 01, 2022
  • Lecture notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
  • Carlos A Rivera A +3
  • PDF
  • Research Article
  • Citations40

Predicting CVSS Metric via Description Interpretation

  • Jan 01, 2022
  • IEEE Access
  • Joana Cabral Costa +4
  • Research Article
  • Citations11

Empirical Validation of Automated Vulnerability Curation and Characterization

  • May 01, 2023
  • IEEE Transactions on Software Engineering
  • Ahmet Okutan +6
  • Research Article
  • Citations20

Transferability of Machine Learning Algorithm for IoT Device Profiling and Identification

  • Jan 15, 2024
  • IEEE Internet of Things Journal
  • Priscilla Kyei Danso +6
  • Research Article
  • Citations84

A multi-target approach to estimate software vulnerability characteristics and severity scores

  • Sep 13, 2018
  • Journal of Systems and Software
  • Georgios Spanos +1
  • Conference Article
  • Citations41

CVExplorer: Multidimensional Visualization for Common Vulnerabilities and Exposures

  • Dec 01, 2018
  • Vung Pham +1
  • Research Article
  • Citations2

BVTED: A Specialized Bilingual (Chinese–English) Dataset for Vulnerability Triple Extraction Tasks

  • Aug 20, 2024
  • Applied Sciences
  • Kai Liu +4
  • Conference Article
  • Citations81

Finding A Needle in a Haystack: Automated Mining of Silent Vulnerability Fixes

  • Nov 01, 2021
  • Jiayuan Zhou +6
  • Research Article
  • Citations1

Threat intelligence named entity recognition techniques based on few-shot learning

  • Sep 01, 2024
  • Array
  • Haiyan Wang +4
  • Conference Article

A FMEA Analysis on Web Applications

  • May 30, 2023
  • Gabriel Petrică +1
  • Conference Article
  • Citations14

SQL Injection Vulnerability Identification from Text

  • Feb 25, 2021
  • Dhruv Parashar +2
  • Book Chapter

Chapter 9 - Security Metrics for Risk-aware Automated Policy Management

  • Nov 11, 2010
  • Autonomic Network Management Principles
  • E Al-Shaer +3
  • Book Chapter
  • Citations4

Towards a Vulnerability Tree Security Evaluation of OpenStack’s Logical Architecture

  • Jan 01, 2014
  • Doudou Fall +3
  • Conference Article
  • Citations13

Understanding vulnerabilities in plugin-based web systems

  • Sep 10, 2018
  • Oslien Mesa +6
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.