Using Large Language Models to Extract Planning Knowledge from Common Vulnerabilities and Exposures

dc.contributor.authorOates, Tim
dc.contributor.authorAlford, Ron
dc.contributor.authorJohnson, Shawn
dc.contributor.authorHall, Cory
dc.date.accessioned2024-10-01T18:05:13Z
dc.date.available2024-10-01T18:05:13Z
dc.date.issued2024
dc.description2024 Workshop on Knowledge Engineering for Planning and Scheduling, Banff, Canada, June 2-3, 2024
dc.description.abstractUnderstanding attackers’ goals and plans is crucial for cyber defense, which relies on understanding the basic steps that attackers can take to exploit vulnerabilities. There is a wealth of knowledge about vulnerabilities in text, such as Common Vulnerabilities and Exposures (CVEs), that is accessible to humans but not machines. This paper presents a system, called CLLaMP, that uses large language models (LLMs) to extract declarative representations of CVEs as planning operators represented using the Planning Domain Description Language (PDDL). CLLaMP ingests CVEs, stores them in a database, uses an LLM to extract a PDDL action that specifies preconditions for, and the effects of, the exploit, and updates the database with the action. The resulting planning operators can be used for automatically recognizing attacker plans in real time. We propose metrics for evaluating the quality of extracted operators and show the translation results for a set of randomly selected CVEs.
dc.description.urihttps://icaps24.icaps-conference.org/program/workshops/keps-papers/KEPS-24_paper_12.pdf
dc.format.extent8 pages
dc.genreconference papers and proceedings
dc.identifierdoi:10.13016/m2l9b7-xlvm
dc.identifier.citationOates, Tim, Ron Alford, Shawn Johnson, and Cory Hall. “Using Large Language Models to Extract Planning Knowledge from Common Vulnerabilities and Exposures,” In Proceedings of 2024 Workshop on Knowledge Engineering for Planning and Scheduling (June 2024). https://icaps24.icaps-conference.org/program/workshops/keps-papers/KEPS-24_paper_12.pdf.
dc.identifier.urihttp://hdl.handle.net/11603/36547
dc.language.isoen_US
dc.publisherInternational Conference on Automated Planning and Scheduling (ICAPS)
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Faculty Collection
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department
dc.rightsThis item is likely protected under Title 17 of the U.S. Copyright Law. Unless on a Creative Commons license, for uses protected by Copyright Law, contact the copyright holder or the author.
dc.titleUsing Large Language Models to Extract Planning Knowledge from Common Vulnerabilities and Exposures
dc.typeText

Files