vulnerability data
Deep VULMAN: A Deep Reinforcement Learning-Enabled Cyber Vulnerability Management Framework
Hore, Soumyadeep, Shah, Ankit, Bastian, Nathaniel D.
Cyber vulnerability management is a critical function of a cybersecurity operations center (CSOC) that helps protect organizations against cyber-attacks on their computer and network systems. Adversaries hold an asymmetric advantage over the CSOC, as the number of deficiencies in these systems is increasing at a significantly higher rate compared to the expansion rate of the security teams to mitigate them in a resource-constrained environment. The current approaches are deterministic and one-time decision-making methods, which do not consider future uncertainties when prioritizing and selecting vulnerabilities for mitigation. These approaches are also constrained by the sub-optimal distribution of resources, providing no flexibility to adjust their response to fluctuations in vulnerability arrivals. We propose a novel framework, Deep VULMAN, consisting of a deep reinforcement learning agent and an integer programming method to fill this gap in the cyber vulnerability management process. Our sequential decision-making framework, first, determines the near-optimal amount of resources to be allocated for mitigation under uncertainty for a given system state and then determines the optimal set of prioritized vulnerability instances for mitigation. Our proposed framework outperforms the current methods in prioritizing the selection of important organization-specific vulnerabilities, on both simulated and real-world vulnerability data, observed over a one-year period.
CTI4AI: Threat Intelligence Generation and Sharing after Red Teaming AI Models
Nguyen, Chuyen, Morgan, Caleb, Mittal, Sudip
One such early As the practicality of Artificial Intelligence (AI) and Machine Learning effort is MITRE ATLAS (Adversarial Threat Landscape for Artificial- (ML) based techniques grow, there is an ever increasing threat Intelligence Systems) knowledge base [8] modeled after the MITRE of adversarial attacks. There is a need to'red team' this ecosystem ATT&CK framework [9]. ATLAS includes a well-defined overview to identify system vulnerabilities, potential threats, characterize of adversary tactics, techniques, and case studies for AI systems properties that will enhance system robustness, and encourage the based on real-world observations and demonstrations from AI security creation of effective defenses. A secondary need is to share this groups, and from academic research. AI security threat intelligence between different stakeholders like, In this paper, to overcome the need to methodically identify and model developers, users, and AI/ML security professionals. In this share AI/ML specific vulnerabilities and threat intelligence we create paper, we create and describe a prototype system CTI4AI, to overcome and describe a prototype system CTI4AI. The system leverages the need to methodically identify and share AI/ML specific DARPA's GARD AI red teaming toolkit to identify vulnerabilities vulnerabilities and threat intelligence.
Machine Learning Can Use Tweets to Spot Critical Security Flaws
At the endless booths of this week's RSA security trade show in San Francisco, an overflowing industry of vendors will offer any visitor an ad nauseam array of "threat intelligence" and "vulnerability management" systems. But it turns out that there's already a decent, free feed of vulnerability information that can tell systems administrators what bugs they really need to patch, updated 24/7: Twitter. And one group of researchers has not only measured the value of Twitter's stream of bug data but is also building a piece of free software that automatically tracks it to pull out hackable software flaws and rate their severity. Researchers at Ohio State University, the security company FireEye, and research firm Leidos last week published a paper describing a new system that reads millions of tweets for mentions of software security vulnerabilities, and then, using their machine-learning-trained algorithm, assessed how much of a threat they represent based on how they're described. They found that Twitter can not only predict the majority of security flaws that will show up days later on the National Vulnerability Database--the official register of security vulnerabilities tracked by the National Institute of Standards and Technology--but that they could also use natural language processing to roughly predict which of those vulnerabilities will be given a "high" or "critical" severity rating with better than 80 percent accuracy.
Machine Learning Can Use Tweets To Automatically Spot Critical Security Flaws
At the endless booths of this week's RSA security trade show in San Francisco, an overflowing industry of vendors will offer any visitor an ad nauseam array of "threat intelligence" and "vulnerability management" systems. But it turns out that there's already a decent, free feed of vulnerability information that can tell systems administrators what bugs they really need to patch, updated 24/7: Twitter. And one group of researchers has not only measured the value of Twitter's stream of bug data, but is also building a piece of free software that automatically tracks it to pull out hackable software flaws and rate their severity. Researchers at Ohio State University, the security company FireEye, and research firm Leidos last week published a paper describing a new system that reads millions of tweets for mentions of software security vulnerabilities, and then, using their machine-learning-trained algorithm, assessed how much of a threat they represent based on how they're described. They found that Twitter can not only predict the majority of security flaws that will show up days later on the National Vulnerability Database--the official register of security vulnerabilities tracked by the National Institute of Standards and Technology--but that they could also use natural language processing to roughly predict which of those vulnerabilities will be given a "high" or "critical" severity rating with better than 80 percent accuracy.