Connecting the Dots: An Integrated Vulnerability Knowledge Graph for Security Practitioners
Loading...
Date
Journal Title
Journal ISSN
Volume Title
Publisher
IEEE
DOI
10.1109/IRI66576.2025.00050
Abstract
Vulnerability databases are essential to cybersecurity, providing developers with critical information about software security flaws. However, inconsistencies among vulnerability databases pose challenges for integration. To address this, we created a graph database that consolidates data from the National Vulnerability Database (NVD), GitHub Advisories, the Open Source Vulnerability (OSV) database, the Exploit Prediction Scoring System (EPSS), and the CWE-1000 View. Our graph database revealed inconsistent vulnerability severity vectors across the databases. To illustrate the utility of our graph database, we investigated how the databases reported the "top ten" most routinely exploited vulnerabilities. Our analysis revealed differences in vulnerability identifiers, and the Common Weakness Enumeration (CWE) mappings of the top ten vulnerabilities. By aggregating vulnerability information from disparate sources, this graph database supports cross-validation, increases transparency, and enables efficient complex queries.
Description
Citation
B. Boles, C. Izurieta and A. M. Reinhold, "Connecting the Dots: An Integrated Vulnerability Knowledge Graph for Security Practitioners," 2025 IEEE International Conference on Information Reuse and Integration and Data Science (IRI), San Jose, CA, USA, 2025, pp. 228-233, doi: 10.1109/IRI66576.2025.00050. keywords: {Databases;Soft sensors;Data integrity;Static analysis;Knowledge graphs;Data science;Vectors;Real-time systems;Rough surfaces;Software development management;Vulnerability graph database;Common Weakness Enumeration;Exploit Prediction Scoring System},