arrow
Return

DeepWukong: Statically Detecting Software Vulnerabilities Using Deep Graph Neural Network

delete2021-04-23
delete157
PRE
AI
X
Xiao Cheng
H
Haoyu Wang
J
Jiayi Hua
G
Guoai Xu *
Y
Yulei Sui
DOI:10.1145/3436877delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Static bug detection has shown its effectiveness in detecting well-defined memory errors, e.g., memory leaks, buffer overflows, and null dereference. However, modern software systems have a wide variety of vulnerabilities. These vulnerabilities are extremely complicated with sophisticated programming logic, and these bugs are often caused by different bad programming practices, challenging existing bug detection solutions. It is hard and labor-intensive to develop precise and efficient static analysis solutions for different types of vulnerabilities, particularly for those that may not have a clear specification as the traditional well-defined vulnerabilities. This article presents DeepWukong, a new deep-learning-based embedding approach to static detection of software vulnerabilities for C/C++ programs. Our approach makes a new attempt by leveraging advanced recent graph neural networks to embed code fragments in a compact and low-dimensional representation, producing a new code representation that preserves high-level programming logic (in the form of controland data-flows) together with the natural language information of a program. Our evaluation studies the top 10 most common C/C++ vulnerabilities during the past 3 years. We have conducted our experiments using 105,428 real-world programs by comparing our approach with fourwell-known traditional static vulnerability detectors and three state-of-the-art deep-learning-based approaches. The experimental results demonstrate the effectiveness of our research and have shed light on the promising direction of combining program analysis with deep learning techniques to address the general static code analysis challenges.
Keywords:
Static analysis
graph embedding
vulnerabilities
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

A
ACM Transactions on Software Engineering and Methodology
IF:
6.2
Papers:
1.2K
Citations:
3.4K

Organization

B
beijing university of posts & telecommunications
Scholars:
1.4W
Papers: 1.2W
Citations: 9
U
university of technology sydney
Scholars:
1.6W
Papers: 2.0W
Citations: 25
Cited Papers

Cited Papers

errShare
errSave
Charge state of ∼1 to 50 keV ions after passing through graphene and ultrathin carbon foils
err2014-02-04
err0
errOAAI
errFrédéric Allegrini; Robert W. Ebert; Stephen A. Fuselier; Georgios Nicolaou; Peter Bedworth; Steve Sinton; Karlheinz J. Trattner
errShare
errSave
err
IF0
err
err0
errOAAI
err
errShare
errSave
researcher View more