Skip to main content

CVE analyzer

This project aims to extract from a collection of vulnerabilities report expressed in common English language various semantic information. These semantic information are encoded and retrieved using Name Entity recognition (NER) on the description and currently the available labels are the following:

  • FUNCTION: Vulnerable function name.
  • VERSION: Vulnerable version of the target program.
  • SOURCECE: Path to the source code that contains the vulnerable function/functions.
  • DRIVER: Driver that we the attacker needs to interact with to trigger the exploit.
  • STRUCT: Malformed struct that contains the bug.
  • VULNERABILITY: Type of the vulnerability (e.g. buffer overflow, etc...).
  • CAPABILITY: Capability that the attacker gains after a successful exploitation of the vulnerability (e.g. remote code execution, etc...).

Dataset

The dataset on which the initial state of the project has been developed and tested on is the list of Common Vulnerability Exposure (CVE) regarding the Linux kernel for the years 2017 and 2018 (for this first implementation). The dataset can be found on the website CVE detail

The dataset is formatted as a Comma Separated Values (CSV) but it has been simplified from it's original version and only the description fields has been taken into account.

Installation

Install the project and al its dependencies with:

pip install cve_analyzer

Metadata

Release files for cve-analyzer 0.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cve-analyzer 0.0.4
File Size Uploaded
cve_analyzer-0.0.4.tar.gz 12.1 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for cve-analyzer 0.0.4
File Interpreter ABI Platform
cve_analyzer-0.0.4-py2.py3-none-any.whl Python 3, Python 2 none any Details

Total release size: 24.1 MB

Release files / cve_analyzer-0.0.4.tar.gz

Download URL cve_analyzer-0.0.4.tar.gz
Size 12.1 MB
Tags Source
SHA-256 checksum
How to use checksums
86c6542013bf7a85055c8b07a87a39c54666cc1bdf6e868cc12da48ec9e9e3af
BLAKE2b-256 checksum
How to use checksums
8386ca2dc5c8b88d8dd6f2bed148d4623296d1d656e2767f96231488e40495fd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.13.0 pkginfo/1.5.0.1 requests/2.19.1 setuptools/40.4.3 requests-toolbelt/0.9.1 tqdm/4.31.1 CPython/2.7.15rc1

Release files / cve_analyzer-0.0.4-py2.py3-none-any.whl

Download URL cve_analyzer-0.0.4-py2.py3-none-any.whl
Size 12.1 MB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
5182822e1aba293c768414b43b374a1955b535ff2e7a3e269c36b6063b7c10ab
BLAKE2b-256 checksum
How to use checksums
0d5e36f21af0453abb3b3f1026c2ca8a22369a6853284079569017f475898a50
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/1.13.0 pkginfo/1.5.0.1 requests/2.19.1 setuptools/40.4.3 requests-toolbelt/0.9.1 tqdm/4.31.1 CPython/2.7.15rc1

Release history Release notifications | RSS feed

This release

0.0.4 This release

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page