Show simple item record

dc.contributor.authorKekül, Hakan
dc.contributor.authorErgen, Burhan
dc.contributor.authorArslan, Halil
dc.date.accessioned2022-05-12T08:14:24Z
dc.date.available2022-05-12T08:14:24Z
dc.date.issued2021tr
dc.identifier.citationKekül, H., Ergen, B., & Arslan, H. (2021). A multiclass hybrid approach to estimating software vulnerability vectors and severity score. Journal of Information Security and Applications, 63, 103028.tr
dc.identifier.urihttps://www.sciencedirect.com/science/article/abs/pii/S2214212621001939
dc.identifier.urihttps://hdl.handle.net/20.500.12418/12884
dc.description.abstractClassifying detected software vulnerabilities is an important process. However, the metric values of security vectors are manually determined by humans, which takes time and may introduce errors stemming from human nature. These metrics are important because of their role in the calculation of vulnerability severity. It is necessary to use machine learning algorithms and data mining techniques to improve the quality and speed of vulnerability analysis and discovery processes. However, studies in this area are still limited. In this study, vulnerability vectors were estimated using the natural language processing techniques bag of words, term frequency–inverse document frequency, and n-gram for feature extraction together with various multiclass classification algorithms, namely Naïve Bayes, decision tree, k-nearest neighbors, multilayer perceptron, and random forest. Our experiments using a large public dataset facilitate assessment and provide a standard-compliant prediction model for classifying software vulnerability vectors. The results show that the joint use of different techniques and classification algorithms is a promising solution to a multi-probability and difficult-to-predict problem. In addition, our study fills an important gap in its field in terms of the size of the dataset used and because it covers a vulnerability scoring system version that has not yet been extensively studied.tr
dc.publisherElseviertr
dc.relation.isversionof10.1016/j.jisa.2021.103028tr
dc.rightsinfo:eu-repo/semantics/openAccesstr
dc.subjectSoftware securitytr
dc.subjectSoftware vulnerabilitytr
dc.subjectInformation securitytr
dc.subjectText analysistr
dc.subjectMulticlass classificationtr
dc.titleA multiclass hybrid approach to estimating software vulnerability vectors and severity scoretr
dc.typearticletr
dc.relation.journalJournal of Information Security and Applicationstr
dc.contributor.departmentMühendislik Fakültesitr
dc.contributor.authorID0000-0003-3286-5159tr
dc.identifier.volume63tr
dc.identifier.issue103028tr
dc.identifier.endpage21tr
dc.identifier.startpage1tr
dc.relation.publicationcategoryUluslararası Hakemli Dergide Makale - Kurum Öğretim Elemanıtr


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record