Expected Exploitability: Predicting the Development of Functional Vulnerability Exploits
Octavian Suciu, Connor Nelson, Zhuoer Lyu, Tiffany Bao, Tudor Dumitras
摘要
Assessing the exploitability of software vulnerabilities at the time of disclosure is difficult and error-prone, as features extracted via technical analysis by existing metrics are poor predictors for exploit development. Moreover, exploitability assessments suffer from a class bias because "not exploitable" labels could be inaccurate.
To overcome these challenges, we propose a new metric, called Expected Exploitability (EE), which reflects, over time, the likelihood that functional exploits will be developed. Key to our solution is a time-varying view of exploitability, a departure from existing metrics. This allows us to learn EE using data-driven techniques from artifacts published after disclosure, such as technical write-ups and proof-of-concept exploits, for which we design novel feature sets.
This view also allows us to investigate the effect of the label biases on the classifiers. We characterize the noisegenerating process for exploit prediction, showing that our problem is subject to the most challenging type of label noise, and propose techniques to learn EE in the presence of noise.
On a dataset of 103,137 vulnerabilities, we show that EE increases precision from 49% to 86% over existing metrics, including two state-of-the-art exploit classifiers, while its precision substantially improves over time. We also highlight the practical utility of EE for predicting imminent exploits and prioritizing critical vulnerabilities.
We develop EE into an online platform which is publicly available at https://exploitability.app/.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Identifying Affected Libraries and Their Ecosystems for Open Source Software VulnerabilitiesSusheng Wu, Wenyan Song, Kaifeng Huang, Bihuan Chen 等ICSE 2024 · 被引用 9 次
- Opportunistic Data Flow Integrity for Real-time Cyber-physical Systems Using Worst Case Execution Time ReservationYujie Wang, Ao Li, Jinwen Wang, Sanjoy K. Baruah 等USENIX Security 2024 · 被引用 8 次
- An Investigation of Interaction and Information Needs for Protocol Reverse Engineering AutomationSamantha Katcher, James Mattei, Jared Chandler, Daniel VotipkaCHI 2025 · 被引用 7 次
- Propagation-Based Vulnerability Impact Assessment for Software Supply ChainsBonan Ruan, Zhiwei Lin, Jiahao Liu, Chuqi Zhang 等ASE 2025 · 被引用 2 次
它引用的顶会 Paper6
- TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and TimeFeargus Pendlebury, Fabio Pierazzi, Roberto Jordaney, Johannes Kinder 等USENIX Security 2019 · 被引用 441 次
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu 等USENIX Security 2018 · 被引用 138 次
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing 等USENIX Security 2018 · 被引用 124 次
- Economic Factors of Vulnerability Trade and ExploitationLuca AllodiCCS 2017 · 被引用 82 次
相关 Paper
- Conflicting Scores, Confusing Signals: An Empirical Study of Vulnerability Scoring SystemsViktoria Koscinski, Mark Nelson, Ahmet Okutan, Robert Falso 等CCS 2025 · 被引用 1 次
- Towards More Practical Automation of Vulnerability AssessmentShengyi Pan, Lingfeng Bao, Jiayuan Zhou, Xing Hu 等ICSE 2024 · 被引用 8 次
- DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task LearningTriet Huynh Minh Le, David Hin, Roland Croft, Muhammad Ali BabarASE 2021 · 被引用 62 次
- V2E: Validating Smart Contract Vulnerabilities through Profit-Driven Exploit Generation and ExecutionJingwen Zhang, Yuhong Nan, Kaiwen Ning, Mingxi Ye 等FSE 2026
- Attacker Control and Bug PrioritizationGuilhem Lacombe, Sébastien BardinUSENIX Security 2025
