Abstract
As Internet of Things (IoT) ecosystems expand into critical infrastructure, the accurate identification of attack patterns, known as vulnerability-to-tactic and technique (VTT) mapping, becomes a critical requirement for cybersecurity. However, applying VTT mapping to the IoT domain faces problems: the data sparsity, where fragmented vulnerability reports lack standardized descriptions, and the explainability deficit, where 'blackbox' predictions pose risks of physical operational disruption. To address these challenges, we propose VDM-IoT, a framework that synergizes knowledge graphs (KGs) with large language models (LLMs). The framework constructs an IoT-enhanced vulnerability KG (VKG) from MITRE database/National Vulnerability Database (NVD). For each target vulnerability, it 1) employs a context-aware similarity mechanism to compensate for information sparsity by retrieving topologically related neighbors; 2) filters explicit reasoning paths to potential targets; and 3) guides the LLM to generate verifiable mappings with natural language justifications. Evaluations on the BRON-based benchmark and our constructed expert-labeled VTT dataset show that VDM-IoT achieves 35.37% Hit@1 in technique mapping and 98.11% accuracy in tactic mapping.
| Original language | English |
|---|---|
| Pages (from-to) | 17105-17120 |
| Number of pages | 16 |
| Journal | IEEE Internet of Things Journal |
| Volume | 13 |
| Issue number | 8 |
| DOIs | |
| State | Published - 2026 |
| Externally published | Yes |
Keywords
- Context
- Internet of Things (IoT)
- knowledge graph (KG)
- large language model (LLM)
- techniques and tactics
- vulnerability
Fingerprint
Dive into the research topics of 'VDM-IoT: Context Enhanced Knowledge Graph-Prompted LLMs for Internet of Things Vulnerability Description Mappings'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver