CAV-STIXGen
收藏资源简介:
CAV-STIXGen是由阿拉巴马大学研究团队构建的专注于网联与自动驾驶汽车领域的安全漏洞结构化知识数据集。该数据集包含183条经过人工标注的记录,每条记录将来自国家漏洞数据库的CVE文本描述映射为结构化的威胁情报表达式,具体涵盖STIX领域对象、STIX关系对象、通用缺陷枚举以及MITRE ATT&CK攻击技术映射。其构建过程通过关键词筛选、相关性过滤、人工标注STIX对象与关系、映射CWE与ATT&CK技术,并最终验证转换为STIX 2.1 JSON格式文件完成。该数据集旨在为评估大语言模型在自动化生成结构化威胁情报方面的性能提供基准,并助力安全从业者系统分析汽车领域漏洞,识别重复出现的攻击模式与弱点,从而优先部署防御措施。
CAV-STIXGen is a structured knowledge dataset focused on security vulnerabilities in the Connected and Autonomous Vehicles (CAV) domain, constructed by a research team from the University of Alabama. This dataset contains 183 manually annotated records, each mapping the textual descriptions of Common Vulnerabilities and Exposures (CVE) entries from the National Vulnerability Database (NVD) to structured threat intelligence expressions, specifically covering STIX Domain Objects (SDOs), STIX Relationship Objects (SROs), Common Weakness Enumeration (CWE), and MITRE ATT&CK attack technique mappings. Its construction workflow includes keyword screening, relevance filtering, manual annotation of STIX objects and relationships, mapping to CWE and ATT&CK techniques, followed by final validation and conversion into STIX 2.1 JSON format files. This dataset aims to provide a benchmark for evaluating the performance of Large Language Models (LLMs) in automated structured threat intelligence generation, and assist security practitioners in systematically analyzing automotive domain vulnerabilities, identifying recurring attack patterns and weaknesses, thereby enabling prioritized deployment of defensive measures.




