{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:47:53Z","timestamp":1784303273110,"version":"3.55.0"},"reference-count":18,"publisher":"SAGE Publications","issue":"1","license":[{"start":{"date-parts":[[2015,8,25]],"date-time":"2015-08-25T00:00:00Z","timestamp":1440460800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"published-print":{"date-parts":[[2015,8,31]]},"abstract":"<jats:p>In this paper we introduce an objective method for CVSS score calculation. CVSS is a well known and mostly used method for giving priority to software vulnerabilities. Currently it is being calculated by some slightly subjective methods which require enough skill and knowledge. This research shows how we can benefit from natural language description of vulnerabilities for CVSS calculation. The data that were used for implementation and evaluation of the proposed models consists of the available CVE vulnerability descriptions and their corresponding CVSS scores from the OSVDB database. First, feature vectors were extracted using text mining tools and techniques, and then the SVM and Random-Forest algorithms as well as fuzzy systems were examined to predict the concerned CVSS scores. In spite of the fact that SVM and Random-Forest are mostly used and trusted methods in prediction, results of this research bear a witness that using fuzzy systems can give comparable and even better results. In addition, implementation of the fuzzy based system is much easier and faster. Although so far, there have been so little efforts in using the information embedded in textual materials regarding vulnerabilities, this research shows that it will be valuable to utilize them in systems security establishment.<\/jats:p>","DOI":"10.3233\/ifs-151733","type":"journal-article","created":{"date-parts":[[2016,1,15]],"date-time":"2016-01-15T12:21:26Z","timestamp":1452860486000},"page":"89-96","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":58,"title":["An automatic method for CVSS score prediction using vulnerabilities description"],"prefix":"10.1177","volume":"30","author":[{"given":"Atefeh","family":"Khazaei","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering, Yazd University, Yazd, Iran"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammad","family":"Ghasemzadeh","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Yazd University, Yazd, Iran"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vali","family":"Derhami","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Yazd University, Yazd, Iran"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","published-online":{"date-parts":[[2015,8,25]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"CVEEditorial Board.CommonVulnerabilities and Exposures: The Standard for Information Security Vulnerability Names http:\/\/cve.mitre.org\/ (last visited 2014-01-01)."},{"key":"e_1_3_1_3_2","unstructured":"CaiD. Spectral Regression: A Regression Framework for Efficient Regularized Subspace Learning PhD Thesis Department of Computer Science UIUC 2009."},{"key":"e_1_3_1_4_2","unstructured":"Forum of Incident Response and Security Teams (FIRST) Common Vulnerabilities Scoring System (CVSS) http:\/\/www.first.org\/cvss\/ (last visited 2014-25-12)."},{"key":"e_1_3_1_5_2","unstructured":"HanJ. KamberM. and PeiJ. Data Mining: Concepts and Techniques. Third Edition Morgan Kaufmann Publishers 2011."},{"key":"e_1_3_1_6_2","unstructured":"JangJ.S. SunC.T. and MizutaniE. Neuro-Fuzzy and Soft Computing Prentice Hall 1997."},{"key":"e_1_3_1_7_2","unstructured":"WangL.X. A Course in Fuzzy Systems and Control Prentice Hall International Inc 1997."},{"key":"e_1_3_1_8_2","unstructured":"LIBLINEAR: A Library for Large Linear Classification. http:\/\/www.csie.ntu.edu.tw\/cjlin\/liblinear\/ (last visited 2014-01-01)."},{"key":"e_1_3_1_9_2","doi-asserted-by":"crossref","unstructured":"BozorgiM. SaulL.K. SavageS. and VoelkerG.M. Beyond Heuristics: Learning to Classify Vulnerabilities and Predict Exploits. KDD\u201910 2010.","DOI":"10.1145\/1835804.1835821"},{"key":"e_1_3_1_10_2","unstructured":"SholomM.W. NitinI. and TongZ. Fundamentals of Predictive Text Mining Springer Publishing Incorporated Company 2010."},{"key":"e_1_3_1_11_2","unstructured":"Microsoft Corporation. Microsoft Security Response Center Security Bulletin Severity Rating System http:\/\/www.microsoft.com\/technet\/security\/bulletin\/rating.mspx (last visited 2014-25-12)."},{"key":"e_1_3_1_12_2","unstructured":"OSVDB: The Open Source Vulnerability Database http:\/\/osvdb.org\/ (last visited 2014-01-01)."},{"key":"e_1_3_1_13_2","unstructured":"MellP. ScarfoneK. and RomanoskyS. A Complete Guide to the Common Vulnerability Scoring System Version 2.0. Forum of Incident Response and Security Teams (FIRST) 2007."},{"issue":"10","key":"e_1_3_1_14_2","doi-asserted-by":"crossref","DOI":"10.1109\/TSE.2014.2340398","article-title":"Predicting vulnerable software components via text mining","volume":"40","author":"Scandariato R.","year":"2014","unstructured":"ScandariatoR., WaldenJ., HovsepyanA. and JoosenW., Predicting vulnerable software components via text mining, Software Engineering, IEEE Transactions on 40(10) (2014).","journal-title":"Software Engineering, IEEE Transactions on"},{"key":"e_1_3_1_15_2","unstructured":"Random Jungle http:\/\/www.randomjungle.org (last visited 2014-01-01)."},{"key":"e_1_3_1_16_2","doi-asserted-by":"crossref","unstructured":"MokhovS.A. PaquetJ. DebbabiM. The Use of NLP Techniques in Static Code Analysis to Detect Weaknesses and Vulnerabilities In Advances in Artificial Intelligence 27th Canadian Conference on Artificial Intelligence Canadian AI 2014 Montr\u00e9al QC Canada 2014.","DOI":"10.1007\/978-3-319-06483-3_33"},{"key":"e_1_3_1_17_2","unstructured":"SANS Institute. SANS Critical Vulnerability Analysis Archive http:\/\/www.sans.org\/newsletters\/cva\/ (last visited 2014-25-12)."},{"key":"e_1_3_1_18_2","unstructured":"TheWord Vector Tool http:\/\/wvtool.sf.net (last visited 2014-01-01)."},{"key":"e_1_3_1_19_2","unstructured":"United States Computer Emergency Readiness Team (US-CERT) US-CERTVulnerability Note Field Descriptions. http:\/\/www.kb.cert.org\/vuls\/html\/fieldhelp (last visited 2014-25-12)."}],"container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/IFS-151733","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/IFS-151733","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/IFS-151733","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T09:39:03Z","timestamp":1777455543000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/IFS-151733"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,8,25]]},"references-count":18,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2015,8,31]]}},"alternative-id":["10.3233\/IFS-151733"],"URL":"https:\/\/doi.org\/10.3233\/ifs-151733","relation":{},"ISSN":["1064-1246","1875-8967"],"issn-type":[{"value":"1064-1246","type":"print"},{"value":"1875-8967","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,8,25]]}}}