PulseAugur
EN
LIVE 11:28:35

New paper maps CVEs to MITRE ATT&CK using expert-labeled data

A new research paper details a method for mapping Common Vulnerabilities and Exposures (CVEs) to MITRE ATT&CK techniques using a classifier trained on 1,207 expert-labeled CVEs. The study found that using LLM-generated labels for training did not improve performance and even degraded coverage of rare techniques, concluding that human curation is superior to generation for this task. The research also includes code and a live demonstration on a vulnerability lookup website. AI

IMPACT This research highlights the limitations of current LLMs in accurately labeling cybersecurity threats, emphasizing the continued need for expert human curation in critical security applications.

RANK_REASON The cluster contains a research paper detailing a new methodology and findings. [lever_c_demoted from research: ic=1 ai=1.0]

Read on Mastodon — fosstodon.org →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

New paper maps CVEs to MITRE ATT&CK using expert-labeled data

COVERAGE [1]

  1. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs Live on every vulnerability page of https:// vulnera

    📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs Live on every vulnerability page of https:// vulnerability.circl.lu Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-techni…