A multiclass hybrid approach to estimating software vulnerability vectors and severity score

dc.contributor.authorKekul, Hakan
dc.contributor.authorErgen, Burhan
dc.contributor.authorArslan, Halil
dc.date.accessioned2026-08-12T17:36:20Z
dc.date.issued2021
dc.departmentFırat Üniversitesi
dc.description.abstractClassifying detected software vulnerabilities is an important process. However, the metric values of security vectors are manually determined by humans, which takes time and may introduce errors stemming from human nature. These metrics are important because of their role in the calculation of vulnerability severity. It is necessary to use machine learning algorithms and data mining techniques to improve the quality and speed of vulnerability analysis and discovery processes. However, studies in this area are still limited. In this study, vulnerability vectors were estimated using the natural language processing techniques bag of words, term frequency-inverse document frequency, and n -gram for feature extraction together with various multiclass classification algorithms, namely Naive Bayes, decision tree, k-nearest neighbors, multilayer perceptron, and random forest. Our experiments using a large public dataset facilitate assessment and provide a standard-compliant prediction model for classifying software vulnerability vectors. The results show that the joint use of different techniques and classification algorithms is a promising solution to a multi-probability and difficult-to-predict problem. In addition, our study fills an important gap in its field in terms of the size of the dataset used and because it covers a vulnerability scoring system version that has not yet been extensively studied.
dc.description.sponsorshipScientific and Technological Research Council of Turkey (TUB.ITAK) [121E298]
dc.description.sponsorshipThis study is supported by The Scientific and Technological Research Council of Turkey (TUB.ITAK) with project number 121E298.
dc.identifier.doi10.1016/j.jisa.2021.103028
dc.identifier.issn2214-2126
dc.identifier.issn2214-2134
dc.identifier.orcid0000-0003-3244-2615
dc.identifier.orcid0000-0001-6269-8713
dc.identifier.orcid0000-0003-3286-5159
dc.identifier.scopus2-s2.0-85116928322
dc.identifier.scopusqualityQ1
dc.identifier.urihttps://doi.org/10.1016/j.jisa.2021.103028
dc.identifier.urihttps://hdl.handle.net/11508/57888
dc.identifier.volume63
dc.identifier.wosWOS:000707477000002
dc.identifier.wosqualityQ2
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherElsevier
dc.relation.ispartofJournal of Information Security and Applications
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_WoS_20260511
dc.subjectSoftware security
dc.subjectSoftware vulnerability
dc.subjectInformation security
dc.subjectText analysis
dc.subjectMulticlass classification
dc.titleA multiclass hybrid approach to estimating software vulnerability vectors and severity score
dc.typeArticle

Dosyalar