arrow
返回

Detecting Cryptography Misuses With Machine Learning: Graph Embeddings, Transfer Learning and Data Augmentation in Source Code Related Tasks

delete2023-12-01
delete1
PRE
AI
G
Gustavo Eloi de Paula Rodrigues *
A
Alexandre Braga
R
Ricardo Dahab
DOI:10.1109/TR.2023.3237849delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Cryptography is a ubiquitous tool in secure software development in order to guarantee security requirements in general. However, software developers have scarce knowledge about cryptography and rely on limited support tools that cannot properly detect bad uses of cryptography, thus generating vulnerabilities in software. In this work, we extend the scarcely use of machine learning to detect cryptography misuse in source code by using a state of the art deep learning model (i.e., code2vec) through transfer learning to generate features that feed machine learning models. In addition, we compare this approach to previous ones in different types of binary models. Also, we adapt code obfuscation to serve as data augmentation in machine learning source code related tasks. Finally, we show that through transfer learning code2vec can be a competitive feature generator for cryptography misuse detection and simple code obfuscation can be used to generate data to enhance machine learning models training in source code related tasks.
Keyword:
Code obfuscation
cryptography misuse
data augmentation
machine learning
misuse detection
transfer learning

期刊

IEEE Transactions on Reliability 封面图
IEEE Transactions on Reliability
IF:
5.7
论文数:
2.7K
被引数:
8.5K

机构

U
universidade estadual de campinas
学者数:
3.3W
论文数: 2.3W
被引数: 19
引用论文

引用论文

err分享
err收藏
Silicon-nitride waveguide-based integrated photonic circuits for medical diagnostic and other sensing applications
err2019-03-04
err0
PREAI
errRainer Hainberger; Paul Muellner; Stefan Nevlacsil; Alejandro Maese-Novo; Florian Vogelbacher; Moritz Eggeling; Jörg Schotter; Martin Sagmeister; Günther Koppitsch; Jochen Kraft
err分享
err收藏
Leveraging ontologies and machine-learning techniques for malware analysis into Android permissions ecosystems
err2018-09-01
err19
PREAI
errNavarro, Luiz C.; Navarro, Alexandre K. W.; Gregio, Andre; Rocha, Anderson; Dahab, Ricardo
err分享
err收藏
学者 查看更多内容