Ana gezinime geç Aramaya geç Ana içeriğe geç

Automated CVE Triage: Ai-Agent Framework for Scalable Vulnerability Triaging and Security Automation

Araştırma sonucu: Kitap/Rapor/Konferans Bildirisinde BölümKonferans katkısıbilirkişi

Özet

As vulnerability disclosure platforms scale, the manual triage of security reports has become a significant operational burden. Government and industry systems such as the Common Vulnerabilities and Exposures (CVE) database, HackerOne, Bugcrowd, and others rely on teams of analysts to validate vulnerability submissions, reproduce proof-of-concept (PoC) exploits, identify affected software versions, and assign Common Vulnerability Scoring System (CVSS) metrics. This process demands substantial labor and funding, contributing to disclosure backlogs and delayed remediation. In this paper, we propose an AI-agent-based triage framework that automates core tasks traditionally performed by human analysts, which has some limitations on the current model driven centrally by MITRE. Our system integrates large language models (LLMs), implemented as small agentic AI systems trained for specific tasks, with sandboxed terminal environments to autonomously interpret reports, execute PoCs in isolated settings, and generate structured outputs suitable for CVE publication or platform response workflows. Initial results indicate that the framework can significantly reduce triage time and operational costs, offering a scalable and reproducible alternative to manual processing.9

Orijinal dilİngilizce
Ana bilgisayar yayını başlığı2025 18th International Conference on Information Security and Cryptology, ISCTurkiye 2025 - Proceedings
EditörlerAli Aydin Selcuk, Seref Sagiroglu, Oguz Yayla, Cihangir Tezcan
YayınlayanInstitute of Electrical and Electronics Engineers Inc.
ISBN (Elektronik)9798331557102
DOI'lar
Yayın durumuYayınlandı - 2025
Etkinlik18th International Conference on Information Security and Cryptology, ISCTurkiye 2025 - Ankara, Turkey
Süre: 22 Eki 202523 Eki 2025

Yayın serisi

Adı2025 18th International Conference on Information Security and Cryptology, ISCTurkiye 2025 - Proceedings

???event.eventtypes.event.conference???

???event.eventtypes.event.conference???18th International Conference on Information Security and Cryptology, ISCTurkiye 2025
Ülke/BölgeTurkey
ŞehirAnkara
Periyot22/10/2523/10/25

Bibliyografik not

Publisher Copyright:
© 2025 IEEE.

Parmak izi

Automated CVE Triage: Ai-Agent Framework for Scalable Vulnerability Triaging and Security Automation' araştırma başlıklarına git. Birlikte benzersiz bir parmak izi oluştururlar.

Alıntı Yap