BM25 Algorithm Driven Search Tool for Linking Exploits to Vulnerabilities
Ashwini Dalvi, Aditya Ambekar, Faruk Kazi, Sunil Bhirud
Abstract
Ashwini Dalvi, Aditya Ambekar, Faruk Kazi, Sunil Bhirud
Abstract
The vulnerability monitoring and prioritizing could be challenging for enterprise security stakeholders. With a number of vulnerabilities published regularly, few of the vulnerabilities result in real-life attacks. However, no matter how slight the possibility of vulnerabilities could result in an exploit, proactive attention is given to vulnerability related information by the cybersecurity community. Researchers aim to consolidate the information regarding vulnerabilities, including but not limited to CVSS, vulnerability description, vulnerability mentioned on a different platform including social media platforms, dark web. The presented work in this paper is motivated to map released vulnerabilities to exposed exploits and vice versa. The mapping could result in one of the features to approximate the possibility of exploiting a vulnerability. The proposed work is accomplished in the form of a search tool to find relevant vulnerabilities for the given exploit title and vice versa
OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The vulnerability monitoring and prioritizing could be challenging for enterprise security stakeholders. With a number of vulnerabilities published regularly, few of the vulnerabilities result in real-life attacks. However, no matter how slight the possibility of vulnerabilities could result in an exploit, proactive attention is given to vulnerability related information by the cybersecurity community. Researchers aim to consolidate the information regarding vulnerabilities, including but not limited to CVSS, vulnerability description, vulnerability mentioned on a different platform including social media platforms, dark web. The presented work in this paper is motivated to map released vulnerabilities to exposed exploits and vice versa. The mapping could result in one of the features to approximate the possibility of exploiting a vulnerability. The proposed work is accomplished in the form of a search tool to find relevant vulnerabilities for the given exploit title and vice versa
Key concepts: Exploit, Vulnerability (computing), Vulnerability management, Computer science, Computer security, Secure coding, Vulnerability assessment, Data science