发表机构
Université Lumière Lyon 2; Université Claude Bernard Lyon 1; ERIC 69007; INSA Lyon, CITI, Inria(里昂第二大学; 里昂第一大学; ERIC 69007; 里昂高等师范学院,CITI,法国国家信息与自动化研究所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出结合网络安全知识图谱构建与自然语言查询的方法,利用NVD数据在Neo4j中建模,通过AI接口将自然语言转为Cypher,降低查询门槛,提升漏洞数据可访问性。
AI 中文摘要
网络安全漏洞信息分布在众多平台和数据库中,使得研究人员和实践者难以对现有威胁获得统一且结构化的理解。这是网络安全中的一个关键问题,及时获取准确的漏洞信息直接影响风险评估和决策制定。虽然先前的工作表明知识图谱在组织漏洞数据方面是有效的,但在其可访问性方面仍存在一个主要的研究空白,因为查询此类图谱通常需要具备图查询语言(如Cypher)的专业知识。本文旨在通过提出一种将网络安全知识图谱的构建与基于自然语言的交互相结合的方法来解决这一空白。所提出的方法依赖于通过其REST API从国家漏洞数据库(NVD)收集的数据,并使用Neo4j中的标签属性图范式对漏洞、产品、供应商、严重性指标、弱点和引用进行建模。该知识图谱部署在Neo4j Aura云上,并通过一个AI辅助接口进行查询,该接口将自然语言查询转换为Cypher语言。这项工作的关键贡献在于证明了自然语言查询显著降低了与网络安全知识图谱交互的门槛,使得对漏洞数据进行更直观的探索和分析成为可能,从而增强了其对网络安全领域更广泛用户的实际有用性。
英文摘要
Cybersecurity vulnerability information is distributed across numerous platforms and databases, making it difficult for researchers and practitioners to obtain a unified and structured understanding of existing threats. This is a critical issue in cybersecurity, where timely access to accurate vulnerability information directly impacts risk assessment and decision-making. While previous work has shown that knowledge graphs are effective for organizing vulnerability data, a major research gap remains in their accessibility, as querying such graphs typically requires expertise in graph query languages like Cypher. This paper aims to address this gap by proposing an approach that combines the construction of a cybersecurity knowledge graph with natural language-based interrogation. The proposed methodology relies on data collected from the National Vulnerability Database (NVD)(1) through its REST API and models vulnerabilities, products, vendors, severity metrics, weaknesses, and references using the Labeled Property Graph paradigm in Neo4j. The knowledge graph is deployed on Neo4j Aura Cloud and queried through an AI-assisted interface that translates natural language queries into Cypher language. The key contribution of this work is demonstrating that natural language querying significantly lowers the barrier to interacting with cybersecurity knowledge graphs, enabling more intuitive exploration and analysis of vulnerability data, and thereby enhancing their practical usefulness for a broader range of users in the cybersecurity field.