Extensões ao DefectDojo para Priorização de Vulnerabilidades
Palavras-chave:
Cibersegurança, Gerenciamento de Vulnerabilidades, DefectDojo, Inteligência Artificial, Aprendizado de Máquina, Priorização de Vulnerabilidades, XGBoost, Gestão de RiscosSinopse
Equipes de segurança rotineiramente se deparam com mais vulnerabilidades do que conseguem investigar. Apresentamos um sistema de priorização de vulnerabilidades personalizado e sensível ao contexto que combina o feedback de analistas com metadados ricos. Estendemos a interface do DefectDojo para incluir metadados de diferentes fontes relacionados às vulnerabilidades carregadas no sistema, informando o processo de análise de vulnerabilidades. Além de auxiliar analistas, os metadados alimentam um modelo de priorização de vulnerabilidades, que avaliamos em vulnerabilidades identificadas pelo OpenVAS em uma rede universitária. Nossos resultados mostram que o sistema proposto aprende rapidamente a priorizar vulnerabilidades, prometendo uma nova ferramenta para direcionar o esforço dos analistas.
Downloads
Referências
Ahsan, M., Gomes, R., Chowdhury, M. M., and Nygard, K. E. (2021). Enhancing Machine Learning Prediction in Cybersecurity Using Dynamic Feature Selector. Journal of Cybersecurity and Privacy, 1(1):199–218.
Aragão, F., de Oliveira Cardoso, G. P., Rios, I., Oliveira, L., Gimpel, M., Almeida, P., and Cunha, I. (2025). Extensões ao DefectDojo para Priorização de Vulnerabilidades. [link].
Croft, R., Babar, M. A., and Kholoosi, M. M. (2023). Data Quality for Software Vulnerability Datasets. In Proc. IEEE/ACM Intl. Conf. on Software Engineering (ICSE).
de Oliveira Cardoso, G. P., Oliveira, L. B., and Cunha, I. (2024). Identificação de Endereços IP Dinâmicos com Dados Públicos. In Anais SBSeg.
Hassan, W. U., Guo, S., Li, D., Chen, Z., Jee, K., Li, Z., and Bates, A. (2019). NoDoze: Combatting Threat Alert Fatigue with Automated Provenance Triage. In Proceedings of the Network and Distributed System Security Symposium (NDSS).
Jacobs, J., Romanosky, S., Adjerid, I., and Baker, W. (2020). Improving Vulnerability Remediation Through Better Exploit Prediction. Journal of Cybersecurity.
Jaffal, N. O., Alkhanafseh, M. Y., and Mohaisen, D. (2025). Large Language Models in Cybersecurity: Applications, Vulnerabilities, and Defense Techniques. AI.
Jimenez, M., Rwemalika, R., Papadakis, M., Sarro, F., Le Traon, Y., and Harman, M. (2019). The Importance of Accounting for Real-World Labelling When Predicting Software Vulnerabilities. In Proc. ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering.
Khanfir, A., Jimenez, M., Papadakis, M., and Traon, Y. L. (2022). CodeBERT-nt: Code Naturalness via CodeBERT. In 2022 IEEE 22nd International Conference on Software Quality, Reliability and Security (QRS).
Ponta, S. E., Plate, H., and Sabetta, A. (2018). Beyond Metadata: Code-Centric and Usage-Based Analysis of Known Vulnerabilities in Open-Source Software. In 2018 IEEE International Conference on Software Maintenance and Evolution (ICSME).
Rashid, M. B., Hossain, M. S. J., Khan, M. I., Tahora, S., Siddika, A., Prakash, M. I., Yeasmin, S., and Shahriar, H. (2026). A Survey on Large Language Models in Software Security: Opportunities and Threats. Computers.
Shimizu, N. and Hashimoto, M. (2026). Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization. IEEE Access, 14:31407–31424.
Tariq, S., Chhetri, M. B., Nepal, S., and Paris, C. (2025). Alert Fatigue in Security Operations Centres: Research Challenges and Opportunities. ACM Computing Surveys.
Wang, P., Zhou, Y., Sun, B., and Zhang,W. (2019). Intelligent Prediction of Vulnerability Severity Level Based on Text Mining and XGBboost. In Intl. Conf. on Advanced Computational Intelligence.
Zadeh, A., Lavine, B., Zolbanin, H., and Hopkins, D. (2023). A Cybersecurity Risk Quantification and Classification Framework for Informed Risk Mitigation Decisions. Decision Analytics Journal, 9:100328.
Zhou, X., Zhang, T., and Lo, D. (2024). Large Language Model for Vulnerability Detection: Emerging Results and Future Directions. In IEEE/ACM International Conference on Software Engineering (ICSE).
Downloads
Data de publicação
Licença

Este trabalho está licenciado sob uma licença Creative Commons Attribution 4.0 International License.
