Abstract:
Organizations are finding it more and more challenging to keep up with the assessment and prioritizing of threats due to the increasing number of cybersecurity vulnerabilities. Traditional techniques of mapping Common Vulnerabilities and Exposures (CVEs) to the MITRE ATT&CK framework are laborious, slow, and error-prone, requiring deep expertise and significant spending time on it. This study solves the challenge by propos ing an AI-powered solution that automates the CVE–MITRE mapping process utilizing natural language processing and large language models like GPT. This system analyzes unstructured CVE descriptions and intelligently maps them to applicable ATT&CK tactics and procedures, decreasing the strain on security analysts, improving response time, and enhancing the accuracy of threat modeling. The automation intends to assist more effective threat detection, risk assessment, and proactive defensive methods across modern digital