A Survey of Cybersecurity Knowledge Base and Its Automatic Labeling
摘要
With the rapid development of internet technology, cyber attacks such as network intrusions, phishing emails, distributed denial-of-service (DDoS), ransomware and advanced persistent threats (APTs) are becoming increasingly frequent, which is causing significant economic losses to society. The cybersecurity knowledge base is significant for analyzing and defending against cyber attacks. In recent years, a number of highly prestigious knowledge bases such as the Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), Common Attack Pattern Enumeration and Classification (CAPEC) and Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) have been proposed. As an important instrument to connect various cybersecurity knowledge bases, the cybersecurity knowledge graph (CSKG) has also been greatly developed in recent years. This paper mainly investigates the interrelationships among common cybersecurity knowledge bases, focusing on the automatic labeling between different cybersecurity knowledge bases. Firstly, different cybersecurity knowledge bases are introduced and compared, and the cybersecurity knowledge graph (CSKG) is briefly summarized. Secondly, different text classification models are investigated, and automatic labeling for cybersecurity knowledge bases with different classification models is discussed. Thirdly, the possible challenges and future prospects are summarized. Finally, we hope this study would provide meaningful help for constructing the cybersecurity knowledge graph (CSKG).