Ehsan Khodayarseresht (Concordia University), Suryadipta Majumdar (Concordia University), Serguei Mokhov (Concordia University), Mourad Debbabi (Concordia University)

The Common Vulnerabilities and Exposures (CVE) program each year records thousands of known vulnerabilities without actionable context about how these vulnerabilities might be exploited by attackers. On the other hand, the MITRE ATT&CK framework outlines attack tactics, techniques, and procedures (TTPs) without linking them to specific vulnerabilities. While enabling automatic mapping of CVE descriptions to TTPs can allow more accurate and more efficient threat detection and mitigation, existing efforts face several challenges: (i) the lack of large-scale, high-quality datasets linking CVEs to TTPs; (ii) the presence of uneven data distributions and missing key TTPs in the existing datasets; (iii) the difficulty of accurately extracting adversarial behaviors from unstructured CVE descriptions; and (iv) the lack of adaptive learning mechanisms for continuously correcting the mappings. This paper addresses those challenges with textit{NEXUS}, a framework to automatically map CVEs to TTPs. Our evaluation (on a newly built dataset, covering textit{208} TTPs and textit{92K+} CVEs, along with other public datasets) shows that textit{NEXUS} achieves a maximum F1-score of textit{97.94%} in CVE-to-TTP mapping, with the capability to work on new CVE entries, compared to existing works that achieve a maximum of textit{67.68%}.

View More Papers

PhantomMotion: Laser-Based Motion Injection Attacks on Wireless Security Surveillance...

Yan He (University of Oklahoma), Guanchong Huang (University of Oklahoma), Song Fang (University of Oklahoma)

Read More

PrivORL: Differentially Private Synthetic Dataset for Offline Reinforcement Learning

Chen GONG (University of Virginia), Zheng Liu (University of Virginia), Kecen Li (University of Virginia), Tianhao Wang (University of Virginia)

Read More

Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram...

Zihao Liu (Iowa State University), Aobo Chen (Iowa State University), Yan Zhang (Iowa State University), Wensheng Zhang (Iowa State University), Chenglin Miao (Iowa State University)

Read More