Extensions to DefectDojo for Vulnerability Prioritization

Authors

Francisco Aragão, UFMG; Gabriel Pains de Oliveira Cardoso, UFMG; Iago Silva Rios, UFMG; Leonardo Oliveira, UFMG; Matheus Gimpel, UFMG; Pedro Meireles Almeida, UFMG; Italo Cunha, UFMG

Keywords:

Cybersecurity, Vulnerability Management, DefectDojo, Artificial Intelligence, Machine Learning, Vulnerability Prioritization, XGBoost, Risk Management

Synopsis

Security teams routinely face more scanner findings than they can investigate or remediate. We present a context-aware, personalized vulnerability prioritization system that combines analyst feedback with metadata about vulnerabilities, services, and detection mechanisms. We extend DefectDojo to present metadata from multiple sources about vulnerabilities imported in the system, better informing vulnerability assessment. Beyond assisting analysts, the metadata allows us to compute features for a model for prioritizing vulnerabilities, which we evaluate on vulnerabilities identified by OpenVAS on a large university network. Our results show that the proposed model quickly learns to prioritize vulnerabilities, promising a new tool to steer analyst effort.

Downloads

Download data is not yet available.

References

Ahsan, M., Gomes, R., Chowdhury, M. M., and Nygard, K. E. (2021). Enhancing Machine Learning Prediction in Cybersecurity Using Dynamic Feature Selector. Journal of Cybersecurity and Privacy, 1(1):199–218.

Aragão, F., de Oliveira Cardoso, G. P., Rios, I., Oliveira, L., Gimpel, M., Almeida, P., and Cunha, I. (2025). Extensões ao DefectDojo para Priorização de Vulnerabilidades. [link].

Croft, R., Babar, M. A., and Kholoosi, M. M. (2023). Data Quality for Software Vulnerability Datasets. In Proc. IEEE/ACM Intl. Conf. on Software Engineering (ICSE).

de Oliveira Cardoso, G. P., Oliveira, L. B., and Cunha, I. (2024). Identificação de Endereços IP Dinâmicos com Dados Públicos. In Anais SBSeg.

Hassan, W. U., Guo, S., Li, D., Chen, Z., Jee, K., Li, Z., and Bates, A. (2019). NoDoze: Combatting Threat Alert Fatigue with Automated Provenance Triage. In Proceedings of the Network and Distributed System Security Symposium (NDSS).

Jacobs, J., Romanosky, S., Adjerid, I., and Baker, W. (2020). Improving Vulnerability Remediation Through Better Exploit Prediction. Journal of Cybersecurity.

Jaffal, N. O., Alkhanafseh, M. Y., and Mohaisen, D. (2025). Large Language Models in Cybersecurity: Applications, Vulnerabilities, and Defense Techniques. AI.

Jimenez, M., Rwemalika, R., Papadakis, M., Sarro, F., Le Traon, Y., and Harman, M. (2019). The Importance of Accounting for Real-World Labelling When Predicting Software Vulnerabilities. In Proc. ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering.

Khanfir, A., Jimenez, M., Papadakis, M., and Traon, Y. L. (2022). CodeBERT-nt: Code Naturalness via CodeBERT. In 2022 IEEE 22nd International Conference on Software Quality, Reliability and Security (QRS).

Ponta, S. E., Plate, H., and Sabetta, A. (2018). Beyond Metadata: Code-Centric and Usage-Based Analysis of Known Vulnerabilities in Open-Source Software. In 2018 IEEE International Conference on Software Maintenance and Evolution (ICSME).

Rashid, M. B., Hossain, M. S. J., Khan, M. I., Tahora, S., Siddika, A., Prakash, M. I., Yeasmin, S., and Shahriar, H. (2026). A Survey on Large Language Models in Software Security: Opportunities and Threats. Computers.

Shimizu, N. and Hashimoto, M. (2026). Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization. IEEE Access, 14:31407–31424.

Tariq, S., Chhetri, M. B., Nepal, S., and Paris, C. (2025). Alert Fatigue in Security Operations Centres: Research Challenges and Opportunities. ACM Computing Surveys.

Wang, P., Zhou, Y., Sun, B., and Zhang,W. (2019). Intelligent Prediction of Vulnerability Severity Level Based on Text Mining and XGBboost. In Intl. Conf. on Advanced Computational Intelligence.

Zadeh, A., Lavine, B., Zolbanin, H., and Hopkins, D. (2023). A Cybersecurity Risk Quantification and Classification Framework for Informed Risk Mitigation Decisions. Decision Analytics Journal, 9:100328.

Zhou, X., Zhang, T., and Lo, D. (2024). Large Language Model for Vulnerability Detection: Emerging Results and Future Directions. In IEEE/ACM International Conference on Software Engineering (ICSE).

Downloads

Publication date

August 5, 2026

License

Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 International License.