节点文献

基于卷积神经网络的软件漏洞自动分类方法

Software Vulnerability Automatic Classification Method Based on Convolutional Neural Network

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 刘烊侨杨频王炎

【Author】 LIU Yang-qiao;YANG Pin;WANG Yan;College of Cyberspace Security, Sichuan University;

【机构】 四川大学网络空间安全学院

【摘要】 目前基于机器学习的漏洞自动化分类存在特征提取困难,而基于深度学习的漏洞自动化分类存在效果不佳的问题。因此,提出一种基于深度神经网络的漏洞自动化分类模型(Word2Vec-CNN),该模型使用Word2Vec方法构建词向量,利用CNN神经网络模型构造自动漏洞分类器,实现有效的漏洞分类。根据美国国家漏洞数据库(NVD)中所记录的漏洞信息,将其用于验证所提出模型的有效性。并将Word2Vec-CNN模型的分类效果与One-hot-CNN模型、One-hot-RNN模型、Word2Vec-RNN模型以及传统的神经网络、贝叶斯算法在准确率、召回率、精度和F1得分几个方面进行比较,Word2Vec-CNN模型具有更好的性能。

【Abstract】 Nowadays the automatic classification of vulnerabilities based on machine learning has difficulty in feature extraction, and the automatic classification of vulnerabilities based on deep learning has the problem of poor results. Therefore, an automatic vulnerability classification model based on deep neural network(Word2 Vec-CNN) is proposed. This model uses Word2 Vec method to construct word vectors, and uses the CNN neural network model to construct an automatic vulnerability classifier to achieve effective vulnerability classification. Based on the vulnerability information recorded in the US National Vulnerability Database(NVD), it is used to verify the validity of the proposed model. The classification effect of the Word2 Vec-CNN model is compared with the One-hot-CNN model, One-hot-RNN model,Word2 Vec-RNN model, and traditional neural networks and Bayesian algorithms in accuracy, recall, accuracy and F1 score. In terms of comparison, the Word2 Vec-CNN model has better performance.

  • 【文献出处】 现代计算机 ,Modern Computer , 编辑部邮箱 ,2020年15期
  • 【分类号】TP183;TP309
  • 【被引频次】3
  • 【下载频次】206
节点文献中: 

本文链接的文献网络图示:

本文的引文网络