Time-Aware Cybersecurity Knowledge Graph Reasoning Method for Vulnerability Analysis
Mengjie Wang, Kunlin Li, Yunlong Lu, Fan Zhang, Jiangtao Ma, Yaqiong Qiao · IEEE Transactions on Automation Science and Engineering · 2025
In the digital age, software security is essential for the stability of information systems and data protection, yet increasing complexity in software systems has made vulnerabilities a significant cybersecurity threat, leading to data breaches, system crashes, and service disruptions. Traditional vulnerability assessments usually analyze vulnerabilities in isolation, ignoring their time relations and the risk of attackers exploiting multiple vulnerabilities simultaneously, known as co-exploitation. This paper proposes an innovative time-aware cybersecurity knowledge graph (TCG) reasoning method called TCGFormer, which is designed to address these challenges. TCGFormer comprises four modules: (1) an entity encoding module that adjusts attention based on positional information and interaction frequency, (2) a novel attention mechanism for encoding relational topology graphs, (3) a joint sequence encoding module for extracting temporal representations and node relations from historical interactions, and (4) a parameter learning module for predicting entities and relations. Extensive experiments on three public temporal datasets demonstrate that TCGFormer significantly outperforms existing baseline methods, and validation on a cybersecurity knowledge graph dataset—including NVD, CVE details, CWE database, and EDB—further confirms its efficacy in identifying co-exploitation behaviors.