ChatNVD: Advancing Cybersecurity Vulnerability Assessment with Large Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chopra, Shivansh, Ahmad, Hussain, Goel, Diksha, Szabo, Claudia
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908370886197248
author Chopra, Shivansh
Ahmad, Hussain
Goel, Diksha
Szabo, Claudia
author_facet Chopra, Shivansh
Ahmad, Hussain
Goel, Diksha
Szabo, Claudia
contents The increasing frequency and sophistication of cybersecurity vulnerabilities in software systems underscores the need for more robust and effective vulnerability assessment methods. However, existing approaches often rely on highly technical and abstract frameworks, which hinder understanding and increase the likelihood of exploitation, resulting in severe cyberattacks. In this paper, we introduce ChatNVD, a support tool powered by Large Language Models (LLMs) that leverages the National Vulnerability Database (NVD) to generate accessible, context-rich summaries of software vulnerabilities. We develop three variants of ChatNVD, utilizing three prominent LLMs: GPT-4o Mini by OpenAI, LLaMA 3 by Meta, and Gemini 1.5 Pro by Google. To evaluate their performance, we conduct a comparative evaluation focused on their ability to identify, interpret, and explain software vulnerabilities. Our results demonstrate that GPT-4o Mini outperforms the other models, achieving over 92% accuracy and the lowest error rates, making it the most reliable option for real-world vulnerability assessment.
format Preprint
id arxiv_https___arxiv_org_abs_2412_04756
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle ChatNVD: Advancing Cybersecurity Vulnerability Assessment with Large Language Models
Chopra, Shivansh
Ahmad, Hussain
Goel, Diksha
Szabo, Claudia
Cryptography and Security
Computation and Language
The increasing frequency and sophistication of cybersecurity vulnerabilities in software systems underscores the need for more robust and effective vulnerability assessment methods. However, existing approaches often rely on highly technical and abstract frameworks, which hinder understanding and increase the likelihood of exploitation, resulting in severe cyberattacks. In this paper, we introduce ChatNVD, a support tool powered by Large Language Models (LLMs) that leverages the National Vulnerability Database (NVD) to generate accessible, context-rich summaries of software vulnerabilities. We develop three variants of ChatNVD, utilizing three prominent LLMs: GPT-4o Mini by OpenAI, LLaMA 3 by Meta, and Gemini 1.5 Pro by Google. To evaluate their performance, we conduct a comparative evaluation focused on their ability to identify, interpret, and explain software vulnerabilities. Our results demonstrate that GPT-4o Mini outperforms the other models, achieving over 92% accuracy and the lowest error rates, making it the most reliable option for real-world vulnerability assessment.
title ChatNVD: Advancing Cybersecurity Vulnerability Assessment with Large Language Models
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2412.04756