Sais: Self-Adaptive Identification of Security Bug Reports

被引:3
|
作者
Mostafa, Shaikh [1 ]
Findley, Bridgette [1 ]
Meng, Na [2 ]
Wang, Xiaoyin [1 ]
机构
[1] Univ Texas San Antonio, Dept Comp Sci, San Antonio, TX 78249 USA
[2] Virginia Tech, Blacksburg, VA 24061 USA
关键词
Computer bugs; Security; Training; Data models; Databases; Semisupervised learning; Software; Security bug reports; self learning; bug triaging; TEXT CLASSIFICATION;
D O I
10.1109/TDSC.2019.2939132
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Among various bug reports (BRs), security bug reports (SBRs) are unique because they require immediate concealment and fixes. When SBRs are not identified in time, attackers can exploit the vulnerabilities. Prior work identifies SBRs via text mining, which requires a predefined keyword list and trains a classifier with known SBRs and non-security bug reports (NSBRs). The former approach is not reliable, because (1) as the contexts of security vulnerabilities and terminology of SBRs change over time, the predefined list will become out-dated; and (2) users may have insufficient SBRs for training. We introduce a semi-supervised learning-based approach, Sais, to adaptively and reliably identify SBRs. Given a project's BRs containing some labeled SBRs, many more NSBRs, and unlabeled BRs, Sais iteratively mines keywords, trains a classifier based on the keywords from the labeled data, classifies unlabeled BRs, and augments its training data with the newly labeled BRs. Our evaluation shows that Sais is useful for identifying SBRs.
引用
收藏
页码:1779 / 1792
页数:14
相关论文
共 50 条
  • [41] Traffic Modeling and Identification using a Self-adaptive Fuzzy Inference Network
    Tung, Sau Wai
    Quek, Chai
    Guan, Cuntai
    2012 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2012,
  • [42] Identification of switched linear systems using self-adaptive SVR algorithm
    Sellami, Lamaa
    Zidi, Salah
    Abderrahim, Kamel
    2016 24TH MEDITERRANEAN CONFERENCE ON CONTROL AND AUTOMATION (MED), 2016, : 617 - 621
  • [43] A self-adaptive cavitation model based on Omega vortex identification theory
    Qu N.
    Xu K.
    Xiang L.
    Lin R.
    Dang X.
    Tuijin Jishu/Journal of Propulsion Technology, 2024, 45 (02):
  • [44] Self-adaptive pulse shape identification by using Gaussian mixture model
    Cheng, Zhiqiang
    Zhang, Qingxian
    Tan, Heyi
    Dong, Chunhui
    Hou, Xin
    Zhang, Jian
    Li, Xiaozhe
    Xiao, Hongfei
    RADIATION MEASUREMENTS, 2024, 172
  • [45] Automated Extraction of Security Concerns from Bug Reports
    Alqahtani, Sultan S.
    2019 17TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2019, : 327 - 329
  • [46] Self-adaptive differential evoultion
    Jia, Liyuan
    Zhang, Chi
    Zhongnan Daxue Xuebao (Ziran Kexue Ban)/Journal of Central South University (Science and Technology), 2013, 44 (09): : 3759 - 3765
  • [47] Self-Adaptive Network Pruning
    Chen, Jinting
    Zhu, Zhaocheng
    Li, Cheng
    Zhao, Yuming
    NEURAL INFORMATION PROCESSING (ICONIP 2019), PT I, 2019, 11953 : 175 - 186
  • [48] Self-Adaptive Timing Repair
    Giesen, Hans
    Rubin, Raphael
    Gojman, Benjamin
    Dehon, Andre
    IEEE DESIGN & TEST, 2017, 34 (06) : 54 - 62
  • [49] SELF-ADAPTIVE INFORMATION RECORDER
    FURNE, AA
    INSTRUMENTS AND EXPERIMENTAL TECHNIQUES, 1976, 19 (04) : 1046 - 1048
  • [50] ERP Self-Adaptive customizing
    Kassem, Gamal
    Schult, Rene
    2008 3RD INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGIES: FROM THEORY TO APPLICATIONS, VOLS 1-5, 2008, : 1719 - 1723