Threat analysis is continuously growing in importance due to the always-increasing complexity and frequency of cyber attacks. Analyzing threats demands significant effort from security experts: different cybersecurity knowledge bases support this task, but manual efforts are required to correlate heterogeneous sources into a unified view that would enable a more comprehensive assessment. To address this gap, we propose ThreatLinker, a methodology leveraging Natural Language Processing (NLP) to effectively and efficiently associate Common Vulnerabilities and Exposure (CVE) vulnerabilities with Common Attack Pattern Enumeration and Classification (CAPEC) attack patterns. The proposed technique combines semantic similarity with keyword analysis to improve the accuracy of association estimations. We contributed a larger dataset for CVE-CAPEC correlation, and experimental evaluations demonstrate superior performance compared to state-of-the-art models.

ThreatLinker: An NLP-Based Methodology to Automatically Estimate CVE Relevance for CAPEC Attack Patterns / Ciavotta, A., Palma, A., Lenti, S., Bonomi, S.. - (2026), pp. 88-95. (21st European Dependable Computing Conference (EDCC) Canterbury; United Kingdom ) [10.23919/EDCCCPS00001.2026.00024].

ThreatLinker: An NLP-Based Methodology to Automatically Estimate CVE Relevance for CAPEC Attack Patterns

Alessandro Palma
;
Simone Lenti
;
Silvia Bonomi
2026

Abstract

Threat analysis is continuously growing in importance due to the always-increasing complexity and frequency of cyber attacks. Analyzing threats demands significant effort from security experts: different cybersecurity knowledge bases support this task, but manual efforts are required to correlate heterogeneous sources into a unified view that would enable a more comprehensive assessment. To address this gap, we propose ThreatLinker, a methodology leveraging Natural Language Processing (NLP) to effectively and efficiently associate Common Vulnerabilities and Exposure (CVE) vulnerabilities with Common Attack Pattern Enumeration and Classification (CAPEC) attack patterns. The proposed technique combines semantic similarity with keyword analysis to improve the accuracy of association estimations. We contributed a larger dataset for CVE-CAPEC correlation, and experimental evaluations demonstrate superior performance compared to state-of-the-art models.
2026
21st European Dependable Computing Conference (EDCC)
cve; capec; natural language processing; threat analysis; cyber risk
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
ThreatLinker: An NLP-Based Methodology to Automatically Estimate CVE Relevance for CAPEC Attack Patterns / Ciavotta, A., Palma, A., Lenti, S., Bonomi, S.. - (2026), pp. 88-95. (21st European Dependable Computing Conference (EDCC) Canterbury; United Kingdom ) [10.23919/EDCCCPS00001.2026.00024].
File allegati a questo prodotto
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1773925
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact