Enhancing Vulnerability Reports With Automated and Augmented Description Summarization

Hattan Althebeiti, Mohammed Alkinoon, Manar Mohaisen, Saeed Salem, Dae Hun Nyang, David Mohaisen

Research output: Contribution to journalArticlepeer-review

Abstract

Public vulnerability databases, such as the National Vulnerability Database (NVD), document vulnerabilities and facilitate threat information sharing. However, they often suffer from short descriptions and outdated or insufficient information. In this paper, we introduce Zad, a system designed to enrich NVD vulnerability descriptions by leveraging external resources. Zad consists of two pipelines: one collects and filters supplementary data using two encoders to build a detailed dataset, while the other fine-tunes a pre-trained model on this dataset to generate enriched descriptions. By addressing brevity and improving content quality, Zad produces more comprehensive and cohesive vulnerability descriptions. We evaluate Zad using standard summarization metrics and human assessments, demonstrating its effectiveness in enhancing vulnerability information.

Original languageEnglish
Pages (from-to)3003-3015
Number of pages13
JournalIEEE Transactions on Big Data
Volume11
Issue number6
DOIs
StatePublished - 2025

Bibliographical note

Publisher Copyright:
© 2015 IEEE.

Keywords

  • Vulnerability
  • national vulnerability database (NVD)
  • natural language processing summarization
  • transformer

Fingerprint

Dive into the research topics of 'Enhancing Vulnerability Reports With Automated and Augmented Description Summarization'. Together they form a unique fingerprint.

Cite this