Vulnerability Intelligence Alignment via Masked Graph Attention Networks
Yue Qin, Yue Xiao, Xiaojing Liao
Abstract
Cybersecurity vulnerability information is often sourced from multiple channels, such as government vulnerability repositories, individually maintained vulnerability-gathering platforms, or vulnerabilitydisclosure email lists and forums. Integrating vulnerability information from different channels enables comprehensive threat assessment and quick deployment to various security mechanisms. However, automatic integration of vulnerability information, especially those lacking decisive information (e.g., CVE-ID), is hindered by the limitations of today's entity alignment techniques. In our study, we annotate and release the first cybersecuritydomain vulnerability alignment dataset, and highlight the unique characteristics of security entities, including the inconsistent vulnerability artifacts of identical vulnerability (e.g., impact and affected version) in different vulnerability repositories. Based on these characteristics, we propose an entity alignment model, CEAM, for integrating vulnerability information from multiple sources. CEAM equips graph neural network-based entity alignment techniques with two application-driven mechanisms: asymmetric masked aggregation and partitioned attention. These techniques selectively aggregate vulnerability artifacts to learn the semantic embeddings for vulnerabilities by an asymmetric mask, while ensuring that the artifacts critical to the vulnerability identification are always taken more consideration. Experimental results on vulnerability alignment datasets demonstrate that CEAM significantly outperforms state-of-the-art entity alignment methods. CCS CONCEPTS • Computing methodologies → Natural language processing; • Security and privacy;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f44427d1-6858-45f7-b773-3492ae4110f8Cited by top-tier papers1
Ask how each one uses itBuilds on11
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin et al.CCS 2017 · 682 citations
- Towards the Detection of Inconsistencies in Public Security Vulnerability ReportsYing Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing et al.USENIX Security 2019 · 149 citations
- Neighborhood Matching Network for Entity AlignmentYuting Wu, Xiao Liu, Yansong Feng, Zheng Wang et al.ACL 2020 · 122 citations
- Dynamic Knowledge Graph AlignmentYuchen Yan, Lihui Liu, Yikun Ban, Baoyu Jing et al.AAAI 2021 · 100 citations
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 97 citations
Related papers
- Multi-modal Siamese Network for Entity AlignmentLiyi Chen, Zhi Li, Tong Xu, Han Wu et al.KDD 2022 · 82 citations
- Cross-Modal Graph Attention Network for Entity AlignmentBaogui Xu, Chengjin Xu, Bing SuACM MM 2023 · 21 citations
- Time-aware Graph Neural Network for Entity Alignment between Temporal Knowledge GraphsChengjin Xu, Fenglong Su, Jens LehmannEMNLP 2021 · 45 citations
- VulSim: Leveraging Similarity of Multi-Dimensional Neighbor Embeddings for Vulnerability DetectionSamiha Shimmi, Ashiqur Rahman, Mohan Gadde, Hamed Okhravi et al.USENIX Security 2024 · 13 citations
- REA: Robust Cross-lingual Entity Alignment Between Knowledge GraphsShichao Pei, Lu Yu, Guoxian Yu, Xiangliang ZhangKDD 2020 · 44 citations
