Refat Othman

dblp:378/0456 · also Refat Tahseen Othman · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0003-1227-9734ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 4 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 From attack descriptions to vulnerabilities: A sentence transformer-based approach
abstract
In the domain of security, vulnerabilities frequently remain undetected even after their exploitation. In this work, vulnerabilities refer to publicly disclosed flaws documented in Common Vulnerabilities and Exposures (CVE) reports. Establishing a connection between attacks and vulnerabilities is essential for enabling timely incident response, as it provides defenders with immediate, actionable insights. However, manually mapping attacks to CVEs is infeasible, thereby motivating the need for automation. This paper evaluates 14 state-of-the-art (SOTA) sentence transformers for automatically identifying vulnerabilities from textual descriptions of attacks. Our results demonstrate that the multi-qa-mpnet-base-dot-v1 (MMPNet) model achieves superior classification performance when using attack Technique descriptions, with an F 1 -score of 89.0, precision of 84.0, and recall of 94.7. Furthermore, it was observed that, on average, 56% of the vulnerabilities identified by the MMPNet model are also represented within the CVE repository in conjunction with an attack, while 61% of the vulnerabilities detected by the model correspond to those cataloged in the CVE repository. A manual inspection of the results revealed the existence of 275 predicted links that were not documented in the MITRE repositories. Consequently, the automation of linking attack techniques to vulnerabilities not only enhances the detection and response capabilities related to software security incidents but also diminishes the duration during which vulnerabilities remain exploitable, thereby contributing to the development of more secure systems. • Automated vulnerability detection using 14 state-of-the-art sentence transformer models. • multi-qa-mpnet-base-dot-v1 achieves an F1 score of 89.0, outperforming other models (e.g., MiniLM, BERT). • Attack technique information yields the highest accuracy (57.3%) for vulnerability prediction. • 275 missing links between attack techniques and vulnerabilities identified through manual validation. • Open-source code and dataset provided to enable reproducible mapping from attacks to CVEs.
Refat Othman, Diaeddin Rimawi, Bruno Rossi 0001, Barbara Russo
J. Syst. Softw.1
2024 Vulnerability Detection for software-intensive system
abstract
Cyberattacks are becoming more sophisticated, and organizations are constantly under threat from various types of security breaches. To protect against these threats, it is essential to identify the vulnerability and impact of these weaknesses and address them before attackers can exploit them. However, manually identifying and characterizing vulnerability can be a time-consuming and tedious process that adds to the workload of cybersecurity experts. To address this challenge, this research plan presents a doctoral research proposal to automate the process of identifying novel technologies, including learning-based technologies, to infer vulnerabilities from a text about an attack. In addition, this research plan uses natural language processing techniques to extract relevant information from attack text and analyze repositories for known vulnerabilities. This research plan presents an in-depth analysis of the research challenges and goals to understand how innovative technologies can be used to detect and identify vulnerabilities in text about attacks. It also covers the preliminary work done, literature review findings, and threats to validity.
Refat Othman
EASE1
2024 Cybersecurity Defenses: Exploration of CVE Types Through Attack Descriptions
abstract
Vulnerabilities in software security can remain undiscovered even after being exploited. Linking attacks to vulnerabilities helps experts identify and respond promptly to the incident. This paper introduces VULDAT, a classification tool using a sentence transformer MPNET to identify system vulnerabilities from attack descriptions. Our model was applied to 100 attack techniques from the ATT&CK repository and 685 issues from the CVE repository. Then, we compare the performance of VULDAT against the other eight state-of-the-art classifiers based on sentence transformers. Our findings indicate that our model achieves the best performance with F1 score of 0.85, Precision of 0.86, and Recall of 0.83. Furthermore, we found 56% of CVE reports vulnerabilities associated with an attack were identified by VULDAT, and 61% of identified vulnerabilities were in the CVE repository.
Refat Othman, Bruno Rossi 0001, Barbara Russo
SEAA1
2024 A Comparison of Vulnerability Feature Extraction Methods from Textual Attack Patterns
abstract
Nowadays, threat reports from cybersecurity vendors incorporate detailed descriptions of attacks within unstructured text. Knowing vulnerabilities that are related to these reports helps cybersecurity researchers and practitioners understand and adjust to evolving attacks and develop mitigation plans. This paper aims to aid cybersecurity researchers and practitioners in choosing attack extraction methods to enhance the monitoring and sharing of threat intelligence. In this work, we examine five feature extraction methods (TF-IDF, LSI, BERT, MiniLM, RoBERTa) and find that Term Frequency-Inverse Document Frequency (TF-IDF) outperforms the other four methods with a precision of 75% and an F1 score of 64%. The findings offer valuable insights to the cybersecurity community, and our research can aid cybersecurity researchers in evaluating and comparing the effectiveness of upcoming extraction methods.
Refat Othman, Bruno Rossi 0001, Barbara Russo
SEAA1