arrow
返回

Software vulnerable functions discovery based on code composite feature

delete2024-03-01
delete2
PRE
AI
袁
袁雪 (Xue Yuan)
G
Guanjun Lin
H
Huan Mei
Y
Yonghang Tai
J
Jun Zhang *
DOI:10.1016/j.jisa.2024.103718delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Vulnerability identification is crucial to protecting software systems from attacks. Although numerous learningbased solutions have been suggested to assist in vulnerability identification, these approaches often face challenges due to the scarcity of real-world vulnerability data. To extract as much vulnerability information as possible from limited data, we consider obtaining the characteristics of vulnerabilities from different forms of code by leveraging two distinct deep neural models. First, source code functions are considered to be textual sequences, and Gated Recurrent Unit (GRU) is applied to extract serialized features. Then, Abstract Syntax Trees (ASTs) of these functions, which reflects the code structure, are fed to a Gated Graph Recurrent Network (GGRN) to obtain structural features indicative of software vulnerability. To better handle data imbalance issues in real-world scenarios, we employ Random Forest (RF) to construct a predictive model to learn the concatenation of serialized and structural features extracted by GRU and GGRN. To evaluate the proposed approach, we collected 12 open -source projects containing function-level samples and compared the proposed method with a series of baselines, including popular learning-based methods and static analysis tools. The empirical results demonstrate that our proposed approach outperforms the baselines and can identify more vulnerabilities.
Keyword:
Vulnerability detection
Source code
Deep learning
Deep representation learning

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

Y
yunnan normal university
学者数:
4.8K
论文数: 2.7K
被引数: 9
Sanming University 封面图
Sanming University
学者数:
704
论文数: 492
被引数: 476
引用论文

引用论文

Data-Driven Cybersecurity Incident Prediction: A Survey
err2019-01-01
err210
PREAI
errSun, Nan; Zhang, Jun; Rimba, Paul; Gao, Shang; Zhang, Leo Yu; Xiang, Yang
err分享
err收藏
err分享
err收藏
BovdGFE: buffer overflow vulnerability detection based on graph feature extraction
err2022-11-12
err4
PREAI
errLv, Xinghang; Peng, Tao; Chen, Jia; Liu, Junping; Hu, Xinrong; He, Ruhan; Jiang, Minghua; Cao, Wenli
err分享
err收藏
err分享
err收藏
err分享
err收藏
Machine Learning-based Cyber Attacks Targeting on Controlled Information: A Survey
err2021-07-18
err57
errOAAI
errMiao, Yuantian; Chen, Chao; Pan, Lei; Han, Qing-Long; Zhang, Jun; Xiang, Yang
err分享
err收藏
学者 查看更多内容