Task-specific dataset for Bayesian Estimation of Weakness-Class Likelihood for Operational Cyber Defence
收藏资源简介:
Existing vulnerability prioritisation methods emphasise either technical severity, such as the Common Vulnerability Scoring System, or exploitation likelihood, such as the Exploit Prediction Scoring System, but neither helps defenders decide which weakness classes to remediate first after observing a specific MITRE ATT&CK technique. We propose a Bayesian co-occurrence model that estimates the conditional probability of Common Weakness Enumeration (CWE) classes given an ATT&CK technique by integrating three publicly available datasets: the Known Exploited Vulnerabilities (KEV) catalog, the National Vulnerability Database, and the European Repository of Cyber Incidents. A KEV-derived exploitation-frequency distribution is used as the prior, while incident-level technique–CWE co-occurrences provide the conditioning signal. Using a temporal holdout split, we evaluate technique-conditioned CWE rankings against an unconditioned marginal baseline with Normalized Discounted Cumulative Gain (NDCG). Across the four evaluated techniques, the conditioned model improves mean NDCG@10 by 693% over the baseline. The findings indicate that technique-conditioned Bayesian estimation can generate interpretable and operationally useful CWE remediation priorities.



