Machine-Learning Supported Vulnerability Detection in Source Code

被引:3
|
作者
Sonnekalb, Tim [1 ]
机构
[1] German Aerosp Ctr DLR, Inst Data Sci, Jena, Germany
关键词
software security; vulnerabilities; vulnerability detection; source code analysis; machine learning on code;
D O I
10.1145/3338906.3341466
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The awareness of writing secure code rises with the increasing number of attacks and their resultant damage. But often, software developers are no security experts and vulnerabilities arise unconsciously during the development process. They use static analysis tools for bug detection, which often come with a high false positive rate. The developers, therefore, need a lot of resources to mind about all alarms, if they want to consistently take care of the security of their software project. We want to investigate, if machine learning techniques could point the user to the position of a security weak point in the source code with a higher accuracy than ordinary methods with static analysis. For this purpose, we focus on current machine learning on code approaches for our initial studies to evolve an efficient way for finding security-related software bugs. We will create a configuration interface to discover certain vulnerabilities, categorized in CWEs. We want to create a benchmark tool to compare existing source code representations and machine learning architectures for vulnerability detection and develop a customizable feature model. At the end of this PhD project, we want to have an easy-to-use vulnerability detection tool based on machine learning on code.
引用
收藏
页码:1180 / 1183
页数:4
相关论文
共 50 条
  • [1] Machine Learning Techniques For Python']Python Source Code Vulnerability Detection
    Farasat, Talaya
    Posegga, Joachim
    [J]. PROCEEDINGS OF THE FOURTEENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, CODASPY 2024, 2024, : 151 - 153
  • [2] Vulnerability Prediction From Source Code Using Machine Learning
    Bilgin, Zeki
    Ersoy, Mehmet Akif
    Soykan, Elif Ustundag
    Tomur, Emrah
    Comak, Pinar
    Karacay, Leyli
    [J]. IEEE ACCESS, 2020, 8 : 150672 - 150684
  • [3] Machine Learning for Source Code Vulnerability Detection: What Works and What Isn't There Yet
    Marjanov, Tina
    Pashchenko, Ivan
    Massacci, Fabio
    [J]. IEEE SECURITY & PRIVACY, 2022, 20 (05) : 60 - 76
  • [4] Research and Progress on Learning-Based Source Code Vulnerability Detection
    Su X.-H.
    Zheng W.-N.
    Jiang Y.
    Wei H.-W.
    Wan J.-Y.
    Wei Z.-Y.
    [J]. Jisuanji Xuebao/Chinese Journal of Computers, 2024, 47 (02): : 337 - 374
  • [5] Automated Vulnerability Detection in Source Code Using Deep Representation Learning
    Russell, Rebecca L.
    Kim, Louis
    Hamilton, Lei H.
    Lazovich, Tomo
    Harer, Jacob A.
    Ozdemir, Onur
    Ellingwood, Paul M.
    McConley, Marc W.
    [J]. 2018 17TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA), 2018, : 757 - 762
  • [6] Machine-learning based vulnerability analysis of existing buildings
    Ruggieri, Sergio
    Cardellicchio, Angelo
    Leggieri, Valeria
    Uva, Giuseppina
    [J]. AUTOMATION IN CONSTRUCTION, 2021, 132 (132)
  • [7] Machine Learning Methods for Improving Vulnerability Detection in Low-level Code
    Letychevskyi, Oleksandr
    Hryniuk, Yaroslav
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 5750 - 5752
  • [8] Automated Vulnerability Detection in Source Code Using Minimum Intermediate Representation Learning
    Li, Xin
    Wang, Lu
    Xin, Yang
    Yang, Yixian
    Chen, Yuling
    [J]. APPLIED SCIENCES-BASEL, 2020, 10 (05):
  • [9] An Empirical Study on Vulnerability Detection for Source Code Software based on Deep Learning
    Lin, Wei
    Cai, Saihua
    [J]. 2021 21ST INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C 2021), 2021, : 1159 - 1160
  • [10] DiverseVul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability Detection
    Chen, Yizheng
    Ding, Zhoujie
    Alowain, Lamya
    Chen, Xinyun
    Wagner, David
    [J]. PROCEEDINGS OF THE 26TH INTERNATIONAL SYMPOSIUM ON RESEARCH IN ATTACKS, INTRUSIONS AND DEFENSES, RAID 2023, 2023, : 654 - 668