Sais: Self-Adaptive Identification of Security Bug Reports

被引:3
|
作者
Mostafa, Shaikh [1 ]
Findley, Bridgette [1 ]
Meng, Na [2 ]
Wang, Xiaoyin [1 ]
机构
[1] Univ Texas San Antonio, Dept Comp Sci, San Antonio, TX 78249 USA
[2] Virginia Tech, Blacksburg, VA 24061 USA
关键词
Computer bugs; Security; Training; Data models; Databases; Semisupervised learning; Software; Security bug reports; self learning; bug triaging; TEXT CLASSIFICATION;
D O I
10.1109/TDSC.2019.2939132
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Among various bug reports (BRs), security bug reports (SBRs) are unique because they require immediate concealment and fixes. When SBRs are not identified in time, attackers can exploit the vulnerabilities. Prior work identifies SBRs via text mining, which requires a predefined keyword list and trains a classifier with known SBRs and non-security bug reports (NSBRs). The former approach is not reliable, because (1) as the contexts of security vulnerabilities and terminology of SBRs change over time, the predefined list will become out-dated; and (2) users may have insufficient SBRs for training. We introduce a semi-supervised learning-based approach, Sais, to adaptively and reliably identify SBRs. Given a project's BRs containing some labeled SBRs, many more NSBRs, and unlabeled BRs, Sais iteratively mines keywords, trains a classifier based on the keywords from the labeled data, classifies unlabeled BRs, and augments its training data with the newly labeled BRs. Our evaluation shows that Sais is useful for identifying SBRs.
引用
收藏
页码:1779 / 1792
页数:14
相关论文
共 50 条
  • [21] A New Method of Security Bug Reports Analysis
    Xu, Yunwu
    Li, Yan
    IT PROFESSIONAL, 2024, 26 (02) : 49 - 56
  • [22] Security bug reports classification using fasttext
    Sultan S. Alqahtani
    International Journal of Information Security, 2024, 23 : 1347 - 1358
  • [23] A new Self-adaptive PSO based on the identification of planar regions
    Mesa, Eddy
    Velasquez, Juan D.
    Jaramillo, Patricia
    2014 IEEE CONGRESS ON EVOLUTIONARY COMPUTATION (CEC), 2014, : 1937 - 1943
  • [24] Application of self-adaptive segmental threshold to ice thickness identification
    Lu, Jia-Zheng
    Zhang, Hong-Xian
    Fang, Zhen
    Li, Bo
    Gaodianya Jishu/High Voltage Engineering, 2009, 35 (03): : 563 - 567
  • [25] A self-adaptive XCS
    Hurst, J
    Bull, L
    ADVANCES IN LEARNING CLASSIFIER SYSTEMS, 2002, 2321 : 57 - 73
  • [26] Security bug reports classification using fasttext
    Alqahtani, Sultan S.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (02) : 1347 - 1358
  • [27] Self-adaptive resonators
    Rosas, E
    Aboites, V
    Damzen, MJ
    NONLINEAR AND COHERENT OPTICS - LASERS OPTICS '98, 1998, 3684 : 64 - 69
  • [28] Self-adaptive regularization
    Vanzella, W
    Pellegrino, FA
    Torre, V
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2004, 26 (06) : 804 - 809
  • [29] Self-Adaptive Automata
    Borda, Aimee
    Koutavas, Vasileios
    2018 ACM/IEEE CONFERENCE ON FORMAL METHODS IN SOFTWARE ENGINEERING (FORMALISE 2018), 2018, : 64 - 73
  • [30] Self-adaptive hydrogels
    Shoaib, Tooba
    Carmichael, Ariel
    Corman, R.
    Shen, Yun
    Nguyen, Helen
    Ewoldt, Randy
    Espinosa-Marzal, Rosa
    ABSTRACTS OF PAPERS OF THE AMERICAN CHEMICAL SOCIETY, 2017, 254