arrow
Return

BovdGFE: buffer overflow vulnerability detection based on graph feature extraction

delete2022-11-12
delete4
PRE
AI
X
Xinghang Lv
彭涛 (Peng Tao)
J
Jia Chen *
刘军平 cover
刘军平 (Junping Liu)
X
Xinrong Hu
何儒汉 cover
何儒汉 (Ruhan He)
姜明华 cover
姜明华 (Minghua Jiang)
W
Wenli Cao
DOI:10.1007/s10489-022-04214-8delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Automatically detecting buffer overflow vulnerabilities is an important research topic in software security. Recent studies have shown that vulnerability detection performance utilizing deep learning-based techniques can be significantly enhanced. However, due to information loss during code representation, existing approaches cannot learn the features associated with vulnerabilities, leading to a high false negative rate (FNR) and low precision. To resolve the existing problems, we propose a method for buffer overflow vulnerability detection based on graph feature extraction (BovdGFE) in C/C++ programs. BovdGFE constructs the buffer overflow function samples. Then, we present a new representation structure, code representation sequence (CoRS), which incorporates the control flow, data dependencies, and syntax structure of the vulnerable code for reducing information loss during code representation. After the function samples are transformed into CoRS, a deep learning model is used to learn vulnerable features and perform vulnerability classification. The results of the experiments show that BovdGFE improves the precision and FNR by 6.3% and 3.9% respectively compared with state-of-the-art methods, which can significantly improve the capability of vulnerability detection.
Keywords:
Vulnerability detection
Abstract syntax tree
Control flow graph
Data dependency graph
Code representation
Deep learning

Journal

Applied Intelligence cover
Applied Intelligence
IF:
3.5
Papers:
7.5K
Citations:
1.7W

Organization

W
wuhan textile university
Scholars:
6.7K
Papers: 4.0K
Citations: 3