{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,26]],"date-time":"2026-07-26T06:32:56Z","timestamp":1785047576415,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":25,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819544332","type":"print"},{"value":"9789819544349","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T00:00:00Z","timestamp":1762992000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T00:00:00Z","timestamp":1762992000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-4434-9_22","type":"book-chapter","created":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T23:03:15Z","timestamp":1762988595000},"page":"467-492","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["What Matters Most in\u00a0Vulnerabilities? Key Term Extraction for\u00a0CVE-to-CWE Mapping with\u00a0LLMs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9778-4019","authenticated-orcid":false,"given":"Stefano","family":"Simonetto","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ronan","family":"Oosteven","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thijs","family":"Van Ede","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peter","family":"Bosch","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Willem","family":"Jonker","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,11,13]]},"reference":[{"key":"22_CR1","unstructured":"NVD data feeds. https:\/\/nvd.nist.gov\/vuln\/data-feeds. Accessed 23 Jan 2024"},{"key":"22_CR2","series-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-030-63086-7_2","volume-title":"Security and Privacy in Communication Networks","author":"E Aghaei","year":"2020","unstructured":"Aghaei, E., Shadid, W., Al-Shaer, E.: ThreatZoom: hierarchical neural network for CVEs to CWEs classification. In: Park, N., Sun, K., Foresti, S., Butler, K., Saxena, N. (eds.) SecureComm 2020. LNICST, vol. 335, pp. 23\u201341. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-63086-7_2"},{"key":"22_CR3","doi-asserted-by":"publisher","unstructured":"Aota, M., Kanehara, H., Kubo, M., Murata, N., Sun, B., Takahashi, T.: Automation of vulnerability classification from its description using machine learning. In: 2020 IEEE Symposium on Computers and Communications (ISCC), pp.\u00a01\u20137 (2020). https:\/\/doi.org\/10.1109\/ISCC50000.2020.9219568","DOI":"10.1109\/ISCC50000.2020.9219568"},{"key":"22_CR4","doi-asserted-by":"crossref","unstructured":"Bafna, P., Pramod, D., Vaidya, A.: Document clustering: TF-IDF approach. In: 2016 International Conference on Electrical, Electronics, and Optimization Techniques (ICEEOT), pp. 61\u201366. IEEE (2016)","DOI":"10.1109\/ICEEOT.2016.7754750"},{"key":"22_CR5","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1016\/j.ins.2019.09.013","volume":"509","author":"R Campos","year":"2020","unstructured":"Campos, R., Mangaravite, V., Pasquali, A., Jorge, A., Nunes, C., Jatowt, A.: Yake! keyword extraction from single documents using multiple local features. Inf. Sci. 509, 257\u2013289 (2020)","journal-title":"Inf. Sci."},{"key":"22_CR6","unstructured":"CVE Project: CVE project documentation (2023). https:\/\/cveproject.github.io\/docs\/. Accessed 04 Sept 2024"},{"key":"22_CR7","doi-asserted-by":"crossref","unstructured":"Das, et al.: V2W-BERT: a framework for effective hierarchical multiclass classification of software vulnerabilities. In: 2021 IEEE 8th International Conference on Data Science and Advanced Analytics (DSAA), pp. 1\u201312. IEEE (2021)","DOI":"10.1109\/DSAA53316.2021.9564227"},{"key":"22_CR8","unstructured":"Devlin, J., Chang, M.W., Lee, K., Toutanova, K.: BERT: pre-training of deep bidirectional transformers for language understanding (2019)"},{"key":"22_CR9","unstructured":"Dherin, B., Munn, M., Mazzawi, H., Wunder, M., Gonzalvo, J.: Learning without training: the implicit dynamics of in-context learning. arXiv preprint arXiv:2507.16003 (2025)"},{"key":"22_CR10","unstructured":"Dong, Q., et\u00a0al.: A survey on in-context learning. arXiv preprint arXiv:2301.00234 (2022)"},{"key":"22_CR11","doi-asserted-by":"publisher","unstructured":"Grootendorst, M.: Keybert: minimal keyword extraction with BERT (2020). https:\/\/doi.org\/10.5281\/zenodo.4461265","DOI":"10.5281\/zenodo.4461265"},{"key":"22_CR12","doi-asserted-by":"crossref","unstructured":"Han, Z., Li, X., Liu, H., Xing, Z., Feng, Z.: Deepweak: reasoning common software weaknesses via knowledge graph embedding. In: 2018 IEEE 25th International Conference on Software Analysis, Evolution and Reengineering (SANER), pp. 456\u2013466. IEEE (2018)","DOI":"10.1109\/SANER.2018.8330232"},{"issue":"1","key":"22_CR13","first-page":"80","volume":"1","author":"EM Hutchins","year":"2011","unstructured":"Hutchins, E.M., Cloppert, M.J., Amin, R.M., et al.: Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Leading Issues Inf. Warfare Secur. Res. 1(1), 80 (2011)","journal-title":"Leading Issues Inf. Warfare Secur. Res."},{"key":"22_CR14","unstructured":"Javaheripi, M., Bubeck, S.: Phi-2: the surprising power of small language models. In: Proceedings of the Annual Meeting of the Association for Computational Linguistics (ACL), vol. 2, no. 1 (2023), published version"},{"key":"22_CR15","doi-asserted-by":"crossref","unstructured":"Liu, X., Tan, Y., Xiao, Z., Zhuge, J., Zhou, R.: Not the end of story: an evaluation of chatgpt-driven vulnerability description mappings. In: Findings of the Association for Computational Linguistics: ACL 2023, pp. 3724\u20133731 (2023)","DOI":"10.18653\/v1\/2023.findings-acl.229"},{"key":"22_CR16","unstructured":"Mikolov, T., Chen, K., Corrado, G., Dean, J.: Efficient estimation of word representations in vector space. arXiv preprint arXiv:1301.3781 (2013)"},{"key":"22_CR17","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1016\/j.procs.2023.08.176","volume":"222","author":"M Pan","year":"2023","unstructured":"Pan, M., Wu, P., Zou, Y., Ruan, C., Zhang, T.: An automatic vulnerability classification framework based on bigru-textcnn. Procedia Comput. Sci. 222, 377\u2013386 (2023)","journal-title":"Procedia Comput. Sci."},{"key":"22_CR18","unstructured":"Simonetto, S., van Ede, T.S., Bosch, P., Jonker, W.: Text2weak: mapping CVEs to CWEs using description embeddings analysis. In: 4th Workshop on Artificial Intelligence-Enabled Cybersecurity Analytics (2024)"},{"key":"22_CR19","unstructured":"Simonetto, S., Oostveen, R., van Ede, T.S., Bosch, P., Jonker, W.: Knowing your weaknesses is your greatest strength: mapping CVE to CWE by leveraging CWE hierarchy and LLMs (2025)"},{"issue":"2","key":"22_CR20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3624734","volume":"33","author":"J Sun","year":"2023","unstructured":"Sun, J., et al.: Aspect-level information discrepancies across heterogeneous vulnerability reports: severity, types and detection methods. ACM Trans. Softw. Eng. Methodol. 33(2), 1\u201338 (2023)","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"22_CR21","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2023.111790","volume":"204","author":"X Sun","year":"2023","unstructured":"Sun, X., et al.: Automatic software vulnerability assessment by extracting vulnerability elements. J. Syst. Softw. 204, 111790 (2023)","journal-title":"J. Syst. Softw."},{"key":"22_CR22","unstructured":"Touvron, H., et al.: Llama: open and efficient foundation language models (2023). https:\/\/arxiv.org\/abs\/2302.13971"},{"key":"22_CR23","unstructured":"Vaswani, A., et al.: Attention is all you need. In: Advances in Neural Information Processing Systems, vol. 30 (2017)"},{"key":"22_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103070","volume":"126","author":"Q Wang","year":"2023","unstructured":"Wang, Q., Gao, Y., Ren, J., Zhang, B.: An automatic classification algorithm for software vulnerability based on weighted word vector and fusion neural network. Comput. Secur. 126, 103070 (2023)","journal-title":"Comput. Secur."},{"key":"22_CR25","doi-asserted-by":"crossref","unstructured":"Weng, Y., et al.: Large language models are better reasoners with self-verification. arXiv preprint arXiv:2212.09561 (2022)","DOI":"10.18653\/v1\/2023.findings-emnlp.167"}],"container-title":["Lecture Notes in Computer Science","Cryptology and Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-4434-9_22","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,31]],"date-time":"2026-01-31T10:02:12Z","timestamp":1769853732000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-4434-9_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,13]]},"ISBN":["9789819544332","9789819544349"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-4434-9_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,13]]},"assertion":[{"value":"13 November 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CANS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Cryptology and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Osaka","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 November 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 November 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cans2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/cy2sec.comm.eng.osaka-u.ac.jp\/miyaji-lab\/event\/cans2025\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}