Connecting the Dots: An Integrated Vulnerability Knowledge Graph for Security Practitioners

Loading...
Thumbnail Image

Journal Title

Journal ISSN

Volume Title

Publisher

IEEE

DOI

10.1109/IRI66576.2025.00050

Abstract

Vulnerability databases are essential to cybersecurity, providing developers with critical information about software security flaws. However, inconsistencies among vulnerability databases pose challenges for integration. To address this, we created a graph database that consolidates data from the National Vulnerability Database (NVD), GitHub Advisories, the Open Source Vulnerability (OSV) database, the Exploit Prediction Scoring System (EPSS), and the CWE-1000 View. Our graph database revealed inconsistent vulnerability severity vectors across the databases. To illustrate the utility of our graph database, we investigated how the databases reported the "top ten" most routinely exploited vulnerabilities. Our analysis revealed differences in vulnerability identifiers, and the Common Weakness Enumeration (CWE) mappings of the top ten vulnerabilities. By aggregating vulnerability information from disparate sources, this graph database supports cross-validation, increases transparency, and enables efficient complex queries.

Description

Citation

B. Boles, C. Izurieta and A. M. Reinhold, "Connecting the Dots: An Integrated Vulnerability Knowledge Graph for Security Practitioners," 2025 IEEE International Conference on Information Reuse and Integration and Data Science (IRI), San Jose, CA, USA, 2025, pp. 228-233, doi: 10.1109/IRI66576.2025.00050. keywords: {Databases;Soft sensors;Data integrity;Static analysis;Knowledge graphs;Data science;Vectors;Real-time systems;Rough surfaces;Software development management;Vulnerability graph database;Common Weakness Enumeration;Exploit Prediction Scoring System},

Endorsement

Review

Supplemented By

Referenced By

Rights and licensing