arrow
Return

HeVulD: A Static Vulnerability Detection Method Using Heterogeneous Graph Code Representation

delete2024-01-01
delete1
PRE
AI
Y
Yuanming Huang
M
Mingshu He *
王晓娟 cover
王晓娟 (Xiaojuan Wang)
J
Jie Zhang
DOI:10.1109/TIFS.2024.3457162delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Vulnerability detection in source code has been a focal point of research in recent years. Traditional rule-based methods fail to identify complex and unknown vulnerabilities, leading to poor performance. While deep learning (DL)-based methods have improved these shortcomings, there is still room for enhancement. For C/C++ source code, effective vulnerability detection requires considering both the information in code statements and the structural information of the code. Graph-based code representation methods can address this need, but existing approaches often use homogeneous graphs that do not differentiate between various types of code statements or dependencies. Few methods use heterogeneous graphs for C/C++ code representation. This study explores this potential and proposes a new C/C++ vulnerability detection method named HeVulD. HeVulD introduces two node definition approaches and a key-node-based program slicing method, generating heterogeneous graph representations for source code. These representations consist of both heterogeneous nodes and edges, providing a more precise representation of source code. HeVulD achieves an F1-score of 96.4% on the SARD dataset, outperforming nine baseline C/C++ vulnerability detection methods. HeVulD has been tested under adversarial attack scenarios to assess its robustness. Additionally, HeVulD has been tested on ten open-source software projects and the latest CVEs, demonstrating its detection and generalization capabilities in real-world scenarios and its ability to identify unknown vulnerabilities.
Keywords:
Codes
Source coding
Software
Image edge detection
Syntactics
Semantics
Security
Software security
vulnerability detection
deep learning
program analysis
heterogeneous graph representation

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

B
beijing university of posts & telecommunications
Scholars:
1.4W
Papers: 1.2W
Citations: 9
Cited Papers

Cited Papers

VulDeeLocator: A Deep Learning-Based Fine-Grained Vulnerability Detector
err2022-07-01
err87
errOAAI
errLi, Zhen; Zou, Deqing; Xu, Shouhuai; Chen, Zhaoxuan; Zhu, Yawei; Jin, Hai
errShare
errSave
SySeVR: A Framework for Using Deep Learning to Detect Software Vulnerabilities
err2022-07-01
err261
errOAAI
errLi, Zhen; Zou, Deqing; Xu, Shouhuai; Jin, Hai; Zhu, Yawei; Chen, Zhaoxuan
errShare
errSave
Comparison and evaluation of clone detection tools
err2007-09-01
err510
errOAAI
errBellon, Stefan; Koschke, Rainer; Antoniol, Giuliano; Krinke, Jens; Merlo, Ettore
errShare
errSave
A systematic literature review on source code similarity measurement and clone detection: Techniques, applications, and challenges
err2023-10-01
err27
errOAAI
errZakeri-Nasrabadi, Morteza; Parsa, Saeed; Ramezani, Mohammad; Roy, Chanchal; Ekhtiarzadeh, Masoud
errShare
errSave
Improved Glycemic Control through Continuous Glucose Sensor-Augmented Insulin Pump Therapy: Prospective Results from a Community and Academic Practice Patient Registry
err2009-07-01
err0
errOAAI
errOhad Cohen; Anna Körner; Rudolf Chlup; Christos S. Zoupas; Anton K. Ragozin; Krisztina Wudi; Dagmar Bartaskova; Aggelos Pappas; Tamás Niederland; Zoltán Taybani; Lubomir Barák; Andriani Vazeou
errShare
errSave
err
IF0
err
err0
PREAI
err
errShare
errSave
researcher View more