{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:42:20Z","timestamp":1781109740535,"version":"3.54.1"},"reference-count":29,"publisher":"IGI Global Scientific Publishing","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013,7]]},"abstract":"<jats:p>Those who do not learn from past vulnerabilities are bound to repeat it. Consequently, there have been several research efforts to enumerate and categorize software weaknesses that lead to vulnerabilities. The Common Weakness Enumeration (CWE) is a community developed dictionary of software weakness types and their relationships, designed to consolidate these efforts. Yet, aggregating and classifying natural language vulnerability reports with respect to weakness standards is currently a painstaking manual effort. In this paper, the authors present a semi-automated process for annotating vulnerability information with semantic concepts that are traceable to CWE identifiers. The authors present an information-processing pipeline to parse natural language vulnerability reports. The resulting terms are used for learning the syntactic cues in these reports that are indicators for corresponding standard weakness definitions. Finally, the results of multiple machine learning algorithms are compared individually as well as collectively to semi-automatically annotate new vulnerability reports.<\/jats:p>","DOI":"10.4018\/jsse.2013070102","type":"journal-article","created":{"date-parts":[[2013,9,3]],"date-time":"2013-09-03T12:54:26Z","timestamp":1378212866000},"page":"18-41","source":"Crossref","is-referenced-by-count":1,"title":["Semi-Automatic Annotation of Natural Language Vulnerability Reports"],"prefix":"10.4018","volume":"4","author":[{"given":"Yan","family":"Wu","sequence":"first","affiliation":[{"name":"College of Information Science and Technology, University of Nebraska at Omaha, Omaha, NE, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Robin","family":"Gandhi","sequence":"additional","affiliation":[{"name":"College of Information Science and Technology, University of Nebraska at Omaha, Omaha, NE, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Harvey","family":"Siy","sequence":"additional","affiliation":[{"name":"College of Information Science and Technology, University of Nebraska at Omaha, Omaha, NE, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2013070102-0","unstructured":"Abbott, R. P., Chin, J. S., Donnelley, J. E., Konigsford, W. L., Tokubo, S., & Webb, D. A. (1976). The RISOS project: Security analysis and enhancements of computer operating systems. Lawrence Livermore Laboratory TR NBSIR-76-1041."},{"key":"jsse.2013070102-1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2002.1041053"},{"key":"jsse.2013070102-2","author":"T.Aslam","year":"1995","journal-title":"A taxonomy of security faults in the UNIX operating system"},{"key":"jsse.2013070102-3","unstructured":"Bisbey, R., & Hollingworth, D. (1978, May). Protection analysis: Final report. Information Sciences Institute, University of Southern California, ARPA ORDER NO. 2223, ISI\/SR-78-13."},{"key":"jsse.2013070102-4","unstructured":"Bishop, M. (1995, May). A taxonomy of UNIX system and network vulnerabilities. Department of Computer Science University of California at Davis, CSE-95-10."},{"key":"jsse.2013070102-5","doi-asserted-by":"crossref","unstructured":"Chang, Y. Y., Zavarsky, P., Ruhl, R., & Lindskog, D. (2011, October). Trend analysis of the CVE for software vulnerability management. In Proceedings of the IEEE International Conference on Privacy, Security, Risk and Trust (PASSAT 2011) (pp. 1290-1293).","DOI":"10.1109\/PASSAT\/SocialCom.2011.184"},{"key":"jsse.2013070102-6","unstructured":"Christey, S. M. (2005, August). The preliminary list of vulnerability examples for researchers (PLOVER). NIST Workshop Defining the State of the Art of Software Security Tools, Gaithersburg, MD."},{"key":"jsse.2013070102-7","unstructured":"Christey, S. M. (2007) Unforgivable vulnerabilities. Black Hat Briefings, Retrieved December 21, 2012, from http:\/\/cwe.mitre.org\/documents\/unforgivable_vulns\/unforgivable.pdf"},{"key":"jsse.2013070102-8","unstructured":"Christey, S. M., & Martin, R. A. (2007, May). Vulnerability type distribution in CVE. MITRE Report. Retrieved December 21, 2012, from http:\/\/cwe.mitre.org\/documents\/vuln-trends."},{"key":"jsse.2013070102-9","unstructured":"Embley, D. W., Ding, Y., Liddle, S. W., & Vickers, M. (2006). Automatic creation and simplified querying of semantic web content. In Proceedings of First Asian Semantic Conference (ASWC), Beijing China."},{"key":"jsse.2013070102-10","unstructured":"Gandhi, R. A., Siy, H., & Wu, Y. (2010). Studying security vulnerabilities. CrossTalk, The Journal of Defense Software Engineering, Sept\/Oct(2010)."},{"key":"jsse.2013070102-11","doi-asserted-by":"crossref","unstructured":"Hayashi, S., Yoshikawa, T., & Saeki, M. (2010). Sentence-to-code traceability recovery with domain ontologies. In Proceedings of the Asia Pacific Software Engineering Conference (APSEC 2010) (pp. 385-394).","DOI":"10.1109\/APSEC.2010.51"},{"key":"jsse.2013070102-12","author":"M.Howard","year":"2005","journal-title":"19 deadly sins of software security programming flaws and how to fix them"},{"key":"jsse.2013070102-13","first-page":"223","article-title":"Novelles recherches sur la distribution florale.","volume":"44","author":"P.Jaccard","year":"1908","journal-title":"Bulletin de la Soci\u00e9t\u00e9 Vaudoise des Sciences Naturelles"},{"key":"jsse.2013070102-14","doi-asserted-by":"crossref","unstructured":"Landwehr, C. E., Bull, A. R., Mcdermott, J. P., & Choi, W. S. (1994). A taxonomy of computer program security flaws with examples. Information Technology Division, Code 5542, Naval Research Laboratory, Washington, D.C. 20375-5337 in ACM Computing Surveys 26, 3.","DOI":"10.21236\/ADA465587"},{"key":"jsse.2013070102-15","unstructured":"MITRE. (2011a). CAPEC - Common attack pattern enumeration and classification (CAPEC). Retrieved October 28, 2011, from http:\/\/capec.mitre.org"},{"key":"jsse.2013070102-16","unstructured":"MITRE. (2011b). CVE -Common vulnerabilities and exposures (CVE). Retrieved October 28, 2011, from http:\/\/www.cve.mitre.org"},{"key":"jsse.2013070102-17","unstructured":"MITRE. (2011c). CWE -Common weakness enumeration (CWE). Retrieved October 28, 2011, from http:\/\/cwe.mitre.org"},{"key":"jsse.2013070102-18","unstructured":"National Institute of Standards and Technology (NIST). (2012). NVD - National vulnerability database (NVD). Retrieved Dec. 21, 2012, from http:\/\/nvd.nist.gov"},{"key":"jsse.2013070102-19","unstructured":"Open Web Application Security Project (OWASP). (2010). Top ten most critical web application security risks. Retrieved from https:\/\/www.owasp.org\/index.php\/Top_10_2010"},{"key":"jsse.2013070102-20","doi-asserted-by":"crossref","unstructured":"Pham, N. H., Nguyen, T. T., Nguyen, H. A., Wang, X., Nguyen, A. T., & Nguyen, T. N. (2010). Detecting recurring and similar software vulnerabilities. In Proceedings of the International Conference on Software Engineering (ICSE 2010) (pp. 227-230).","DOI":"10.1145\/1810295.1810336"},{"key":"jsse.2013070102-21","unstructured":"Rapid-I. (2012). RapidMiner. Retrieved December 23, 2012, from http:\/\/rapid-i.com\/content\/view\/181\/196"},{"key":"jsse.2013070102-22","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-010-0302-3"},{"key":"jsse.2013070102-23","unstructured":"Stanford, N. L. P. (Natural Language Processing) Group. (2011). Queries as vectors. Retrieved October 28, 2011, from http:\/\/nlp.stanford.edu\/IR-book\/html\/htmledition\/queries-as-vectors-1.html"},{"key":"jsse.2013070102-24","doi-asserted-by":"crossref","unstructured":"Wang, J. A., & Guo, M. (2009, April). OVM: An ontology for vulnerability management. In Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies (CSIIRW '09), Knoxville, TN.","DOI":"10.1145\/1558607.1558646"},{"key":"jsse.2013070102-25","unstructured":"Web Application Security Consortium (WASC). (2010). Threat classification v2.0. Retrieved from http:\/\/www.webappsec.org\/projects\/threat"},{"key":"jsse.2013070102-26","doi-asserted-by":"crossref","unstructured":"Wita, R., Jiamnapanon, N., & Teng-amnuay, Y. (2010, April). An ontology for vulnerability lifecycle. In Proceedings of the International Symposium on Intelligent Information Technology and Security Informatics (IITSI 2010) (pp. 553-557).","DOI":"10.1109\/IITSI.2010.141"},{"key":"jsse.2013070102-27","doi-asserted-by":"crossref","unstructured":"Wu, Y., Gandhi, R. A., & Siy, H. (2010, May). Using semantic templates to study vulnerabilities recorded in large software repositories. In Proceedings of the 6th International Workshop on Software Engineering for Secure Systems (SESS'10) at the 32nd International Conference on Software Engineering (ICSE 2010), South Africa, Cape Town.","DOI":"10.1145\/1809100.1809104"},{"key":"jsse.2013070102-28","doi-asserted-by":"crossref","unstructured":"Wu, Y., Siy, H., & Gandhi, R. A. (2011, May). NIER: Empirical results on the study of software vulnerabilities. In Proceedings of the NIER at the 33rd International Conference on Software Engineering (ICSE 2011), Honolulu, HI.","DOI":"10.1145\/1985793.1985960"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=83633","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,22]],"date-time":"2019-07-22T23:45:14Z","timestamp":1563839114000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2013070102"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2013,7]]},"references-count":29,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2013070102","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2013,7]]}}}