期刊文献+

漏洞数据库的文本聚类分析

Text clustering method on national vulnerability database
下载PDF
导出
摘要 为解决现有软件漏洞分类重叠性和实用性低等问题,提出了在漏洞实例聚类基础上的漏洞分类方法。对漏洞数据库(national vulnerability database,NVD)的漏洞描述字段进行文本聚类,并且使用聚类重叠性指标评估Simplekmean、BisectingKMeans和BatchSom聚类算法的效果,依据领域主导度选择典型的漏洞类型。实验结果显示近NVD中四万条漏洞数据聚类成45类典型漏洞,从而使软件漏洞研究工作从个体研究转变成对主导漏洞类型的研究。 In order to solve the problem of overlap and low efficiency in software vulnerability taxonomies,proposed vulnerability classifying method based on text clustering of vulnerability descriptor fields in NVD(national vulnerability database),and used cluster overlap index to evaluate the performance of Simplekmean,BisectingKMeans and BatchSom clustering algorithms.The experimental results demonstrate that 45 dominant clusters are selected from approximate 40 000 vulnerability records in NVD according to descriptor dominance index,and it transforms the vulnerabilities research focuses from individuals to vulnerability taxonomies.
出处 《计算机应用研究》 CSCD 北大核心 2010年第7期2670-2673,共4页 Application Research of Computers
关键词 漏洞数据库 文本聚类 聚类重叠指标 主导漏洞类型 vulnerability database text clustering cluster overlap index dominant vulnerability taxonomies
  • 相关文献

参考文献5

二级参考文献17

  • 1张永铮,方滨兴,迟悦.计算机弱点数据库综述与评价[J].计算机科学,2006,33(8):19-21. 被引量:8
  • 2冯是聪 单松巍 张志刚 等.一个中文网页数据集及其分类体系[A]..海峡两岸技术交流会[C].南京,2002-10.121-129.
  • 3Yiming Yang,Jan O Pedersen.A comparative Study on Feature Selection in Text Categorization[C].In :Proceedings of the Fourteenth International Conference on Machine Leaming(ICML'97), 1997.
  • 4Yiming Yang,Xin Liu.A re-examination of text categorization methods[C].In:Proceedings of ACM SIGIR Conference on Research and Development in Information Retrieval SIGIR'99,1999:42---49.
  • 5Yiming Yang.A study on thresholding strategies for text categorization[C].In:Proceedings of ACM SIGIR Conference on Research and Development in Information Retrieval(SIGIR'01),2001.
  • 6MITRE. Common Vulnerabilities and Exposures. http,//www. cve. mitre. org
  • 7SecurityFocus Bugtraq Vulnerability Database. http://xforce. com/bid
  • 8National Vulnerability Database. http://nvd. nist. gov
  • 9CERT/CC. CERT/CC Vulnerability Notes Database. http:// www. kb. cert. org/vuls
  • 10Internet Security Systems. X-Force Vulnerability Database. http://xforce. iss. net

共引文献95

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部