arrow
Return

Malicious source code detection using a translation model

delete2023-07-01
delete0
delete
OA
AI
C
Chen Tsfaty
M
Michael Fire *
DOI:10.1016/j.patter.2023.100773delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Modern software development often relies on open-source code sharing. Open-source code reuse, however, allows hackers to access wide developer communities, thereby potentially affecting many products. An increasing number of such supply chain attackshave occurred in recent years, taking advantage of open-source software development practices. Here, we introduce the Malicious Source code Detection using a Translation model (MSDT) algorithm. MSDT is a novel deep-learning-based analysis method that detects real-world code injections into source code packages. We have tested MSDT by embedding exam-ples from a dataset of over 600,000 different functions and then applying a clustering algorithm to the resulting embedding vectors to identify malicious functions by detecting outliers. We evaluated MSDT's performance with extensive experiments and demonstrated that MSDT could detect malicious code injec-tions with precision@k values of up to 0.909.
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Patterns cover
Patterns
IF:
7.4
Papers:
935
Citations:
3.6K

Organization

B
ben gurion university
Scholars:
1.3W
Papers: 1.0W
Citations: 5