A Similarity Approach for the Classification of Mitigations in Public Cybersecurity Repositories into NIST-SP 800-53 Catalog
摘要
By 2025, it is projected that cybercrimes will escalate to an alarming annual figure of 10.5 trillion USD. To counter this growing threat, cybersecurity repositories such as CVE, CWE, CAPEC, and Mitre Att &ck serve as crucial platforms for the exchange of threat intelligence and mitigations. These repositories play a pivotal role in the prevention of cyber threats. Yet, mitigations in these repositories are manually described by various experts, lacking standardized rules and often failing to reference widely accepted catalogs like NIST SP800-53. To enhance the effectiveness and usability of mitigations within security repositories, this paper proposes an automatic classification method for repository mitigations, categorizing them into NIST SP800-53 classes. This classification relies on similarity approaches and introduces a novel algorithm aimed at refining and optimizing the accuracy of the classification results.