A new research paper details a method for mapping Common Vulnerabilities and Exposures (CVEs) to MITRE ATT&CK techniques using a classifier trained on 1,207 expert-labeled CVEs. The study found that using LLM-generated labels for training did not improve performance and even degraded coverage of rare techniques, concluding that human curation is superior to generation for this task. The research also includes code and a live demonstration on a vulnerability lookup website. AI
IMPACT This research highlights the limitations of current LLMs in accurately labeling cybersecurity threats, emphasizing the continued need for expert human curation in critical security applications.
RANK_REASON The cluster contains a research paper detailing a new methodology and findings. [lever_c_demoted from research: ic=1 ai=1.0]
Read on Mastodon — fosstodon.org →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →