Exploitability Evaluation Through Symbolic Reasoning: A Neuro-Symbolic Framework for Vulnerability Management
Resumo
Modern vulnerability management programs face a gap between prioritization and validation: deciding which of thousands of Common Vulnerabilities and Exposures (CVEs) are actually exploitable in a specific environment. Static metrics (CVSS) and probabilistic predictors (EPSS) are insufficient; Breach-and-Attack-Simulation (BAS) tools are expensive and operationally complex. This paper presents a neuro-symbolic multi-agent framework that combines Large Language Models (LLMs) — extracting structured rules from CVE descriptions — with a Prolog engine that performs deterministic, auditable exploitability inference. On four Linux local-privilege-escalation (LPE) CVEs across vulnerable, mitigated, and patched states, the full configuration reaches 100% accuracy versus 61.5% for a single-shot LLM baseline (McNemar p < 10−4) and 92.4% for a no-Prolog ablation, at roughly one quarter of the neural baseline’s token cost. These preliminary results (four Linux LPE CVEs) suggest the approach is a promising direction — rather than a validated general solution — for a lightweight, interpretable validation layer in Continuous Threat Exposure Management (CTEM) programs.
Referências
Bizzarri, A. et al. (2024). A synergistic approach in network intrusion detection by neurosymbolic AI.
Borazjanizadeh, N.; Piantadosi, S. T. (2024). Reliable reasoning beyond natural language. arXiv:2407.11373.
Chen, J. et al. (2023). Vulnerability correlation, multi-step attack and exploit chain in breach and attack simulation. CloudNet 2023.
Elder, S. et al. (2024). A survey on software vulnerability exploitability assessment. ACM Computing Surveys, 56.
d’Avila Garcez, A.; Lamb, L. C. (2023). Neurosymbolic AI: the 3rd wave. Artificial Intelligence Review, 56:12387–12406.
Jacobs, J. et al. (2021). Exploit Prediction Scoring System (EPSS). Digital Threats: Research and Practice, 2.
Jalaian, B.; Bastian, N. D. (2023). Neurosymbolic AI in cybersecurity: bridging pattern recognition and symbolic reasoning. MILCOM 2023.
Kenna Security; Cyentia Institute (2019). Prioritization to Prediction Vol. 4: Measuring what matters in remediation. Technical report.
Malevich, M. (2024). The five steps of CTEM, part 4: Validation. XM Cyber Blog. [link] (accessed on July 29, 2026).
CTEM.org. Continuous Threat Exposure Management (CTEM). [link] (accessed on July 29, 2026).
Piplai, A. et al. (2023). Knowledge-enhanced neurosymbolic AI for cybersecurity and privacy. IEEE Internet Computing, 27:43–48.
Roque, M. S. C. et al. (2024). Implementation of security controls for the treatment of malware using breach and attack simulation. INTERCON 2024.
Spring, J. et al. (2021). Time to change the CVSS? IEEE Security and Privacy, 19:74–78.
Stein, A. (2025). Validation: the engine that powers CTEM. Cymulate Blog. [link] (accessed on July 29, 2026).
Vakharia, P. et al. (2024). ProSLM: a Prolog synergized language model for explainable domain specific knowledge based question answering.
Wan, Z. et al. (2024). Towards cognitive AI systems: a survey and prospective on neurosymbolic AI.
Cohen, M. (2023). Velociraptor — endpoint visibility and collection. [link].
