Automatically Locating Mitigation Information for Security Vulnerabilities
Kylie McClanahan, Qinghua Li · 2020
Software vulnerabilities pose significant security risks to systems. Usually patching can fix vulnerabilities, but patches are not always available, and in many cases patching is not preferred due to high overhead and potential service interruptions which is especially true for the electric industry. Then, other mitigation strategies are needed to mitigate security vulnerabilities. Information about mitigation strategies can be difficult to find and is typically only reported on vendor or third-party websites. In the current practice, such information is manually located by security operators, which induces high delays and operation cost. We consider this problem within the electric industry, which has particular importance and challenges because of its regulatory requirements. We propose that providing electric utilities with automatically-located mitigation information will help them overcome the time burden and mitigate vulnerabilities more timely. In particular, we develop three methods for automatically retrieving mitigation information from vendor or third-party websites. Experiment results show high performance with all the three methods.