{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,9,2]],"date-time":"2026-09-02T01:45:03Z","timestamp":1788313503730,"version":"build-2803163510"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2020,7,21]],"date-time":"2020-07-21T00:00:00Z","timestamp":1595289600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,7,21]],"date-time":"2020-07-21T00:00:00Z","timestamp":1595289600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Syst Assur Eng Manag"],"published-print":{"date-parts":[[2021,2]]},"DOI":"10.1007\/s13198-020-01021-7","type":"journal-article","created":{"date-parts":[[2020,7,21]],"date-time":"2020-07-21T14:04:00Z","timestamp":1595340240000},"page":"58-64","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":40,"title":["Software vulnerability prioritization using vulnerability description"],"prefix":"10.1007","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7994-0307","authenticated-orcid":false,"given":"Ruchi","family":"Sharma","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ritu","family":"Sibal","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sangeeta","family":"Sabharwal","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,7,21]]},"reference":[{"key":"1021_CR1","doi-asserted-by":"publisher","DOI":"10.1007\/s13198-020-00957-0","author":"M Anjum","year":"2020","unstructured":"Anjum M, Agarwal V, Kapur PK, Khatri SK (2020) Two-phase methodology for prioritization and utility assessment of software vulnerabilities. Int J Syst Assur Eng Manag. https:\/\/doi.org\/10.1007\/s13198-020-00957-0","journal-title":"Int J Syst Assur Eng Manag"},{"key":"1021_CR2","doi-asserted-by":"crossref","unstructured":"Bozorgi M, Saul LK, Savage S, Voelker GM (2010) Beyond heuristics: learning to classify vulnerabilities and predict exploits. In:\u00a0Proceedings of the 16th ACM SIGKDD international conference on knowledge discovery and data mining,\u00a0pp 105\u2013114","DOI":"10.1145\/1835804.1835821"},{"key":"1021_CR3","doi-asserted-by":"crossref","unstructured":"Conneau A, Schwenk H, Barrault L, Lecun Y (2016) Very deep convolutional networks for text classification.\u00a0arXiv preprint https:\/\/arXiv.org\/arXiv:1606.01781","DOI":"10.18653\/v1\/E17-1104"},{"key":"1021_CR4","unstructured":"CVE Details (2019) The ultimate security vulnerability data source, www.cvedetails.com. [Online]"},{"key":"1021_CR5","doi-asserted-by":"crossref","unstructured":"Fruhwirth C, Mannisto T (2009) Improving CVSS-based vulnerability prioritization and response with context information. In: 2009 3rd International symposium on empirical software engineering and measurement, pp 535\u2013544. IEEE","DOI":"10.1109\/ESEM.2009.5314230"},{"key":"1021_CR6","doi-asserted-by":"crossref","unstructured":"Han Z, Li X, Xing Z, Liu H, Feng Z (2017) Learning to predict severity of software vulnerability using only vulnerability description. In:\u00a02017 IEEE international conference on software maintenance and evolution (ICSME),\u00a0pp 125\u2013136. IEEE","DOI":"10.1109\/ICSME.2017.52"},{"key":"1021_CR7","unstructured":"https:\/\/www.wildml.com\/2015\/12\/implementing-a-cnn-for-text-classification-in-tensorflow\/, last Accessed 9 May 2020"},{"key":"1021_CR8","doi-asserted-by":"crossref","unstructured":"Ibidapo AO, Zavarsky P, Lindskog D, Ruhl R (2011) An analysis of CVSS v2 environmental scoring. In: 2011 IEEE 3rd international conference on privacy, security, risk and trust and 2011 IEEE third international conference on social computing, pp 1125\u20131130. IEEE","DOI":"10.1109\/PASSAT\/SocialCom.2011.121"},{"key":"1021_CR9","doi-asserted-by":"crossref","unstructured":"Jacobs J, Romanosky S, Adjerid I, Baker W (2019) Improving vulnerability remediation through better exploit prediction. In:\u00a02019 workshop on the economics of information security","DOI":"10.1093\/cybsec\/tyaa015"},{"key":"1021_CR10","unstructured":"Jacobs J, Romanosky S, Edwards B, Roytman M, Adjerid I (2019) Exploit prediction scoring system (EPSS).\u00a0arXiv preprint https:\/\/arXiv.org\/arXiv:1908.04856"},{"key":"1021_CR11","doi-asserted-by":"crossref","unstructured":"Kim Y (2014) Convolutional neural networks for sentence classification.\u00a0arXiv preprint https:\/\/arXiv.org\/arXiv:1408.5882","DOI":"10.3115\/v1\/D14-1181"},{"key":"1021_CR12","doi-asserted-by":"crossref","unstructured":"Kapur PK, Yadavali VS, Shrivastava AK (2015) A comparative study of vulnerability discovery modeling and software reliability growth modeling. In: 2015 International conference on futuristic trends on computational analysis and knowledge management (ABLAZE), pp 246\u2013251). IEEE","DOI":"10.1109\/ABLAZE.2015.7155000"},{"key":"1021_CR13","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-019-09490-1","author":"PK Kudjo","year":"2020","unstructured":"Kudjo, PK, Chen J, Mensah S, Amankwah R, Kudjo C (2020) The effect of Bellwether analysis on software vulnerability severity prediction models.\u00a0Softw Qual J. https:\/\/doi.org\/10.1007\/s11219-019-09490-1","journal-title":"Softw Qual J"},{"issue":"8","key":"1021_CR14","doi-asserted-by":"publisher","first-page":"1699","DOI":"10.1016\/j.jss.2012.03.057","volume":"85","author":"Q Liu","year":"2012","unstructured":"Liu Q, Zhang Y, Kong Y, Wu Q (2012) Improving VRSS-based vulnerability prioritization using analytic hierarchy process. J Syst Softw 85(8):1699\u20131708","journal-title":"J Syst Softw"},{"issue":"3","key":"1021_CR15","doi-asserted-by":"publisher","first-page":"264","DOI":"10.1016\/j.comcom.2010.04.006","volume":"34","author":"Q Liu","year":"2011","unstructured":"Liu Q, Zhang Y (2011) VRSS: a new system for rating and scoring vulnerabilities. Comput Commun 34(3):264\u2013273","journal-title":"Comput Commun"},{"issue":"6","key":"1021_CR16","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1109\/MSP.2006.145","volume":"4","author":"P Mell","year":"2006","unstructured":"Mell P, Scarfone K, Romanosky S (2006) Common vulnerability scoring system. IEEE Secur Priv 4(6):85\u201389","journal-title":"IEEE Secur Priv"},{"key":"1021_CR17","first-page":"23","volume-title":"A complete guide to the common vulnerability scoring system version 2.0","author":"P Mell","year":"2007","unstructured":"Mell P, Scarfone K, Romanosky S (2007) A complete guide to the common vulnerability scoring system version 2.0. FIRST-Forum of Incident Response and Security Teams, North Carolina, vol 1, p 23"},{"issue":"01","key":"1021_CR18","doi-asserted-by":"publisher","first-page":"1850002","DOI":"10.1142\/S021853931850002X","volume":"25","author":"S Narang","year":"2018","unstructured":"Narang S, Kapur PK, Damodaran D, Shrivastava AK (2018) Bi-criterion problem to determine optimal vulnerability discovery and patching time. Int J Reliab Qual Saf Eng 25(01):1850002","journal-title":"Int J Reliab Qual Saf Eng"},{"key":"1021_CR19","doi-asserted-by":"crossref","unstructured":"Narang S, Kapur PK, Damodaran D, Shrivastava AK (2017). User-based multi-upgradation vulnerability discovery model. In: 2017 6th international conference on reliability, infocom technologies and optimization (Trends and Future Directions) (ICRITO), pp 400\u2013405. IEEE","DOI":"10.1109\/ICRITO.2017.8342459"},{"key":"1021_CR20","doi-asserted-by":"crossref","unstructured":"Peng H, Li J, He Y, Liu Y, Bao M, Wang L, Yang Q (2018) Large-scale hierarchical text classification with recursively regularized deep graph-cnn. In:\u00a0Proceedings of the 2018 world wide web conference, pp 1063\u20131072","DOI":"10.1145\/3178876.3186005"},{"key":"1021_CR21","doi-asserted-by":"crossref","unstructured":"Pennington J, Socher R, Manning C (2014) Glove: global vectors for word representation. In:\u00a0Proceedings of the 2014 conference on empirical methods in natural language processing (EMNLP),\u00a0pp 1532\u20131543","DOI":"10.3115\/v1\/D14-1162"},{"key":"1021_CR22","doi-asserted-by":"crossref","unstructured":"Scarfone Karen, and Peter Mell (2009) An analysis of CVSS version 2 vulnerability scoring. In:\u00a0Proceedings of the 2009 3rd international symposium on empirical software engineering and measurement. IEEE computer society","DOI":"10.1109\/ESEM.2009.5314220"},{"key":"1021_CR23","unstructured":"Schiffman M, Cisco CIAG (2005) A complete guide to the common vulnerability scoring system (CVSS). Forum incident response and security teams. https:\/\/www.first.org\/"},{"issue":"4","key":"1021_CR24","doi-asserted-by":"publisher","first-page":"19","DOI":"10.4018\/IJSSE.2016100102","volume":"7","author":"R Sharma","year":"2016","unstructured":"Sharma R, Sibal R, Shrivastava AK (2016) Vulnerability discovery modeling for open and closed source software. Int J Secure Softw Eng (IJSSE) 7(4):19\u201338","journal-title":"International Journal of Secure Software Engineering (IJSSE)"},{"key":"1021_CR26","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-981-10-5577-5_3","volume-title":"Quality IT and business operations","author":"R Sharma","year":"2018","unstructured":"Sharma R, Singh RK (2018) An improved scoring system for software vulnerability prioritization. In: Kapur PK, Kumar U, Verma AK (eds) Quality IT and business operations. Springer, Singapore, pp 33\u201343"},{"key":"1021_CR25","doi-asserted-by":"crossref","unstructured":"Sharma R, Sibal R, Sabharwal S (2018a) Change point modelling in the vulnerability discovery process. In: International conference on advanced informatics for computing research. Springer, Singapore, pp 559\u2013568","DOI":"10.1007\/978-981-13-3143-5_46"},{"key":"1021_CR27","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1007\/978-981-10-7323-6_32","volume-title":"System performance and management analytics","author":"R Sharma","year":"2019","unstructured":"Sharma R, Sibal R, Sabharwal S (2019) Software Vulnerability Prioritization: a comparative study using TOPSIS and VIKOR techniques. In: Kapur PK, Klochkov Y, Verma AK, Singh G (eds) System performance and management analytics. Springer, Singapore, pp 405\u2013418"},{"key":"1021_CR28","doi-asserted-by":"crossref","unstructured":"Shrivastava AK, Sharma R, Kapur PK (2015) Vulnerability discovery model for a software system using stochastic differential equation. In; 2015 International conference on futuristic trends on computational analysis and knowledge management (ABLAZE), pp 199\u2013205. IEEE","DOI":"10.1109\/ABLAZE.2015.7154992"},{"key":"1021_CR29","doi-asserted-by":"crossref","unstructured":"Shrivastava AK, Sharma R (2018) Modeling vulnerability discovery and patching with fixing lag. In: International conference on advanced informatics for computing research. Springer, Singapore, pp 569\u2013578","DOI":"10.1007\/978-981-13-3143-5_47"},{"key":"1021_CR30","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1201\/9780429488009-15","volume-title":"Mathematics and reliability engineering","author":"AK Shrivastava","year":"2019","unstructured":"Shrivastava AK, Kapur PK, Bhatt M (2019) Vulnerability discovery and patch modeling: a state of the art. In: Ram M (ed) Mathematics and reliability engineering. Taylor & Francis, London, pp 401\u2013419"},{"issue":"1","key":"1021_CR31","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1007\/s41872-017-0006-8","volume":"6","author":"R Sibal","year":"2017","unstructured":"Sibal R, Sharma R, Sabharwal S (2017) Prioritizing software vulnerability types using multi-criteria decision-making techniques. Life Cycle Reliab Saf Eng 6(1):57\u201367","journal-title":"Life Cycle Reliab Saf Eng"},{"key":"1021_CR32","first-page":"164","volume":"46","author":"UK Singh","year":"2019","unstructured":"Singh UK, Joshi C, Kanellopoulos D (2019) A framework for zero-day vulnerabilities detection and prioritization. J Inform Secur Appl 46:164\u2013172","journal-title":"J Inform Secur Appl"},{"issue":"1\u20133","key":"1021_CR33","first-page":"57","volume":"24","author":"G Spanos","year":"2015","unstructured":"Spanos G, Angelis L (2015) Impact metrics of security vulnerabilities: analysis and weighing. Inform Secur J: A Global Perspect 24(1\u20133):57\u201371","journal-title":"Inform Secur J: A Global Perspect"},{"key":"1021_CR34","doi-asserted-by":"crossref","unstructured":"Spanos G, Sioziou A, Angelis L (2013) WIVSS: a new methodology for scoring information systems vulnerabilities. In:\u00a0Proceedings of the 17th panhellenic conference on informatics,\u00a0pp 83\u201390. ACM","DOI":"10.1145\/2491845.2491871"},{"key":"1021_CR36","doi-asserted-by":"crossref","unstructured":"Wang S, Huang M, Deng Z (2018) Densely connected CNN with multi-scale feature attention for text classification. In:\u00a0IJCAI,\u00a0pp 4468\u20134474","DOI":"10.24963\/ijcai.2018\/621"},{"issue":"2","key":"1021_CR37","doi-asserted-by":"crossref","first-page":"579","DOI":"10.1007\/978-3-642-33506-8_71","volume":"8","author":"Y Wang","year":"2012","unstructured":"Wang Y, Yang Y (2012) PVL: a novel metric for single vulnerability rating and its application in IMS. J Comput Inform Syst 8(2):579\u2013590","journal-title":"J Comput Inform Syst"},{"key":"1021_CR38","unstructured":"Zhang Y, Wallace B (2015) A sensitivity analysis of (and practitioners' guide to) convolutional neural networks for sentence classification.\u00a0arXiv preprint https:\/\/arXiv.org\/arXiv:1510.03820"}],"container-title":["International Journal of System Assurance Engineering and Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13198-020-01021-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13198-020-01021-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13198-020-01021-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,11,3]],"date-time":"2022-11-03T19:46:11Z","timestamp":1667504771000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13198-020-01021-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,21]]},"references-count":37,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,2]]}},"alternative-id":["1021"],"URL":"https:\/\/doi.org\/10.1007\/s13198-020-01021-7","relation":{},"ISSN":["0975-6809","0976-4348"],"issn-type":[{"value":"0975-6809","type":"print"},{"value":"0976-4348","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,7,21]]},"assertion":[{"value":"9 May 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 June 2020","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 July 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}