arrow
返回

Detecting code vulnerabilities by learning from large-scale open source repositories

delete2022-09-01
delete5
delete
OA
AI
R
Rongze Xu
Z
Zhanyong Tang *
G
Guixin Ye
H
Huanting Wang
X
Xin Ke
D
Dingyi Fang
Z
Zheng Wang
DOI:10.1016/j.jisa.2022.103293delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Machine learning methods are widely used to identify common, repeatedly occurring bugs and code vulnerabilities. The performance of a machine-learned model is bounded by the quality and quantity of training data and the model's capability in extracting and capturing the essential information of the problem domain. Unfortunately, there is a storage of high-quality samples for training code vulnerability detection models, and existing machine learning methods are inadequate in capturing code vulnerability patterns.We present DEVELOPER,(1 )a novel learning framework for building code vulnerability detection models. To address the data scarcity challenge, DEVELOPER automatically gathers training samples from open-source projects and applies constraints rules to the collected data to filter out noisy data to improve the quality of the collected samples. The collected data provides many real-world vulnerable code training samples to complement the samples available in standard vulnerable databases. To build an effective code vulnerability detection model, DEVELOPER employs a convolutional neural network architecture with attention mechanisms to extract code representation from the program abstract syntax tree. The extracted program representation is then fed to a downstream network - a bidirectional long-short term memory architecture - to predict if the target code contains a vulnerability or not. We apply DEVELOPER to identify vulnerabilities at the program source-code level. Our evaluation shows that DEVELOPER outperforms state-of-the-art methods by uncovering more vulnerabilities with a lower false-positive rate.
Keyword:
Code vulnerability detection
Deep learning
Attention mechanism
Software vulnerability
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

N
northwest university xi'an
学者数:
1.8W
论文数: 1.2W
被引数: 22
U
university of leeds
学者数:
3.6W
论文数: 3.3W
被引数: 45
引用论文

引用论文

err分享
err收藏
err分享
err收藏
Charge state of ∼1 to 50 keV ions after passing through graphene and ultrathin carbon foils
err2014-02-04
err0
errOAAI
errFrédéric Allegrini; Robert W. Ebert; Stephen A. Fuselier; Georgios Nicolaou; Peter Bedworth; Steve Sinton; Karlheinz J. Trattner
err分享
err收藏
err分享
err收藏
err分享
err收藏
Production of reactive oxygen species from abraded silicates. Implications for the reactivity of the Martian soil
err2017-09-01
err0
PREAI
errEbbe N. Bak; Kaloyan Zafirov; Jonathan P. Merrison; Svend J. Knak Jensen; Per Nørnberg; Haraldur P. Gunnlaugsson; Kai Finster
err分享
err收藏
Diminished Sphingolipid Metabolism, a Hallmark of Future Type 2 Diabetes Pathogenesis, Is Linked to Pancreatic β Cell Dysfunction
err2020-10-01
err0
errOAAI
errSaifur R. Khan; Yousef Manialawy; Andreea Obersterescu; Brian J. Cox; Erica P. Gunderson; Michael B. Wheeler
err分享
err收藏
学者 查看更多内容