Open question: is there anyone having some ideas on taxonomy efforts for computer networks vulnerabilities, a la MITRE? I was looking at this paper, but don't know whether anything better/clearer/more recent could be found? https://www.researchgate.net/publication/253306786_Being_Explicit_about_Security_Weaknesses
Dunno if any of these are relevant to your efforts, but here are some candidate papers I found on arXiv [1706.09772] The Security Assessment Domain: A Survey of Taxonomies and Ontologies https://arxiv.org/abs/1706.09772 [2103.03530] Cyber Threat Intelligence Model: An Evaluation of Taxonomies, Sharing Standards, and Ontologies within Cyber Threat Intelligence https://arxiv.org/abs/2103.03530 [1902.03914] Taxonomy driven indicator scoring in MISP threat intelligence platforms https://arxiv.org/abs/1902.03914 [2102.11498] V2W-BERT: A Framework for Effective Hierarchical Multiclass Classification of Software Vulnerabilities https://arxiv.org/abs/2102.11498 [2010.00533] Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting https://arxiv.org/abs/2010.00533