Utilizing attack enumerations to study SDN/NFV vulnerabilities
Quang-Vinh Dang, Jérôme François · 2018
Several cybersecurity attack enumerations area available today. These enumerations present lists of known attack patterns (CAPEC), security weaknesses (CWE) or cybersecurity vulnerabilities (CVE). These enumerations are being developed separately and manually. In this paper, we present the efforts in determining the relations between enumerations automatically. We rely on text-based, graph-based and recommendation-based approaches. Then we present of using the prediction in recommending related attacks to SDN/NFV security issues. Experimental results showed that we can actually infer real relations. Furthermore, the results gave some insights into how the enumerations are created and linked, and some suggestions to improve the process in the future.