International Journal of Computer Techniques Volume 12 Issue 4 | Modernising Vulnerability Prioritisation: Automated Risk Scoring Using Generative AI
Modernising Vulnerability Prioritisation: Automated Risk Scoring Using Generative AI
International Journal of Computer Techniques – Volume 12 Issue 4, July – August 2025
ISSN: 2394-2231 | https://ijctjournal.org
Abstract
This paper introduces a microservice-based framework that leverages Generative AI and large language models (LLMs) to automate vulnerability risk scoring. Traditional CVSS-based systems lack real-time context and adaptability. The proposed system retrieves unranked vulnerabilities from a MySQL database, constructs structured prompts, queries an LLM for contextual scoring, and updates the database with dynamic risk scores. This approach enhances prioritisation accuracy and supports more responsive cybersecurity workflows.
Keywords
Vulnerability Prioritization, Generative AI, Microservice Architecture, Risk Scoring, CVSS
Conclusion
This research presents a novel, automated risk scoring system using LLMs to enhance vulnerability prioritisation. By integrating prompt engineering, microservices, and real-time scoring, the system complements static CVSS models with contextual intelligence. Future enhancements include integrating live exploit feeds and adaptive feedback loops to further refine prioritisation accuracy and responsiveness.
References
- Cloud Security Alliance. AI’s Impact on Vulnerability Management. 2024.
- Burke, J. How AI Will Transform Vulnerability Management. TechTarget, 2024.
- IBM Security Intelligence. AI-Driven Vulnerability Management. 2024.
- Jiang, Y. et al. A Systematic Review of AI for Vulnerability Prioritization. arXiv:2502.11070v1, 2025.
- Krishnan, V. V. Generative AI for Vulnerability Management: A Blueprint. Scientific Research and Community, 2024.
Post Comment