arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ThreatLens:证据引导的高优先级CVE排名

ThreatLens: Evidence-Guided Ranking of High-Priority CVEs

Soroush Motamedi Sedeh, Panteha Shahrivar, Malaika Qureshi, Ali Devjiani, Mohammad A. Tayebi

arXiv 2608.22306首次发表:更新:

AI 中文总结

ThreatLens是一种用于CVE优先级排序的框架,仅用截止时有效证据排名,以CISA KEV为弱监督,在时间向前、CVE不相交评估中优于CVSS等基线,能高效覆盖未来KEV CVE并实现及时分类。

AI 中文摘要

安全团队必须在漏洞利用证据完整前对漏洞进行优先级排序。现有信号如CVSS、EPSS、安全公告和公开漏洞利用虽有用,但零散且具时间敏感性;回顾性排名因使用决策时不可用的证据,可能夸大性能。本文提出ThreatLens,这是一种简单、有效且部署符合实际的CVE优先级排序框架。ThreatLens仅使用截止时有效的证据,在每个审查点对漏洞进行排名,并以未来CISA KEV条目作为利用相关性的弱监督进行学习。在时间向前、CVE不相交的评估下,ThreatLens显著优于CVSS、EPSS和基于规则的证据融合基线。在保留的测试拆分中,ThreatLens在Top20中覆盖了80.0%的未来KEV CVE,是相同预算下EPSS的三倍多,在Top50中达到95.9%。预警分析进一步显示,ThreatLens在正式目录纳入前识别了大量后续KEV条目,支持及时、基于证据的分类。

英文摘要

Security teams must prioritize vulnerabilities before exploitation evidence is complete. Existing signals, such as CVSS, EPSS, advisories, and public exploits, are useful but fragmented and time-sensitive; retrospective rankings can therefore overstate performance by using evidence unavailable at decision time. We present ThreatLens, a simple yet effective and deployment-realistic framework for CVE prioritization. ThreatLens ranks vulnerabilities at each review point using only cutoff-valid evidence and learns from future CISA KEV entries as weak supervision for exploitation relevance. Under forward-in-time, CVE-disjoint evaluation, ThreatLens significantly outperforms CVSS, EPSS, and rule-based evidence-fusion baselines. On the held-out test split, ThreatLens surfaces 80.0% of future KEV CVEs in the top 20, over three times EPSS at the same budget, and reaches 95.9% in the top 50. Early-warning analysis further shows that ThreatLens identifies a substantial fraction of subsequent KEV entries before formal catalog inclusion, supporting timely, evidence-grounded triage.

Comments8 pages, 3 figures, 4 tables. Accepted to the CIKM 2026 Applied Research Track

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑