A Study on NLP-Based Semi-automated Mapping of Cybersecurity Controls on Vulnerabilities
摘要
Chief Security Officers (CISOs) and cybersecurity analysts face significant challenges in managing the vast amount of information addressed by security frameworks, particularly when they lack expertise in industrial sectors characterized by specific cybersecurity regulations. Reviewing and analyzing these frameworks requires considerable effort, making it difficult to identify and select appropriate countermeasures for effective risk mitigation. In response to this challenge, our research aims to alleviate the burden on security experts by providing a semi-automated mapping process that links identified vulnerabilities to security controls, extracted from available frameworks, that may be used in a response action. To achieve our goal, we apply NLP models to compare the degree of similarity between sets of vulnerabilities and sets of controls extracted from cybersecurity frameworks. We show that a high degree of similarity between the vulnerability and control descriptions as indicated by NLP, means that there is a high chance that the control is effective in mitigating the linked vulnerability. We demonstrate the validity of our approach, by using two distinct NLP models on two case studies (cloud and operational technology security frameworks) and assessing their outcomes. Our research may improve decision-making by streamlining the cybersecurity analysts’ risk assessment process.