Machine learning techniques for software vulnerability prediction: a comparative study

被引:8
|
作者
Jabeen, Gul [1 ,2 ]
Rahim, Sabit [2 ]
Afzal, Wasif [3 ]
Khan, Dawar [4 ,5 ]
Khan, Aftab Ahmed [2 ]
Hussain, Zahid [2 ]
Bibi, Tehmina [6 ]
机构
[1] Tsinghua Univ, Beijing, Peoples R China
[2] Karakoram Int Univ, Dept Comp Sci, Gilgit, Pakistan
[3] Malardalen Univ, Vasteras, Sweden
[4] Chinese Acad Sci, Shenzhen Inst Adv Technol, Shenzhen, Peoples R China
[5] Univ Haripur, Dept Informat Technol, Haripur, Pakistan
[6] Univ Azad Jammu & Kashmir, Inst Geol, Muzaffarabad, Pakistan
关键词
Software vulnerability; Machine learning; Prediction models; DISCOVERY; MCMCBAYES; SYSTEMS; MODEL;
D O I
10.1007/s10489-022-03350-5
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Software vulnerabilities represent a major cause of security problems. Various vulnerability discovery models (VDMs) attempt to model the rate at which the vulnerabilities are discovered in a software. Although several VDMs have been proposed, not all of them are universally applicable. Also most of them seldom give accurate predictive results for every type of vulnerability dataset. The use of machine learning (ML) techniques has generally found success in a wide range of predictive tasks. Thus, in this paper, we conducted an empirical study on applying some well-known machine learning (ML) techniques as well as statistical techniques to predict the software vulnerabilities on a variety of datasets. The following ML techniques have been evaluated: cascade-forward back propagation neural network, feed-forward back propagation neural network, adaptive-neuro fuzzy inference system, multi-layer perceptron, support vector machine, bagging, M5Rrule, M5P and reduced error pruning tree. The following statistical techniques have been evaluated: Alhazmi-Malaiya model, linear regression and logistic regression model. The applicability of the techniques is examined using two separate approaches: goodness-of-fit to see how well the model tracks the data, and prediction capability using different criteria. It is observed that ML techniques show remarkable improvement in predicting the software vulnerabilities than the statistical vulnerability prediction models.
引用
收藏
页码:17614 / 17635
页数:22
相关论文
共 50 条
  • [1] Machine learning techniques for software vulnerability prediction: a comparative study
    Gul Jabeen
    Sabit Rahim
    Wasif Afzal
    Dawar Khan
    Aftab Ahmed Khan
    Zahid Hussain
    Tehmina Bibi
    [J]. Applied Intelligence, 2022, 52 : 17614 - 17635
  • [2] A Comparative Study of Machine Learning Techniques for Caries Prediction
    Montenegro, Robson D.
    Oliveira, Adriano L. I.
    Cabral, George G.
    Katz, Cintia R. T.
    Rosenblatt, Aronita
    [J]. 20TH IEEE INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, VOL 2, PROCEEDINGS, 2008, : 477 - +
  • [3] A Study on Software Effort Prediction Using Machine Learning Techniques
    Zhang, Wen
    Yang, Ye
    Wang, Qing
    [J]. EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING, ENASE 2011, 2013, 275 : 1 - 15
  • [4] Comprehensive Study on Machine Learning Techniques for Software Bug Prediction
    Khleel, Nasraldeen Alnor Adam
    Nehez, Karoly
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (08) : 726 - 735
  • [5] A Comparative Study of Machine Learning Techniques for Nuanced Weather Prediction
    Gangula, Prashanth Reddy
    Yeboah, Jones
    Nti, Isaac Kofi
    [J]. 2023 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE, CSCI 2023, 2023, : 260 - 265
  • [6] An empirical study of software reliability prediction using machine learning techniques
    Pradeep Kumar
    Yogesh Singh
    [J]. International Journal of System Assurance Engineering and Management, 2012, 3 (3) : 194 - 208
  • [7] An empirical study of software reliability prediction using machine learning techniques
    Kumar, Pradeep
    Singh, Yogesh
    [J]. INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2012, 3 (03) : 194 - 208
  • [8] Comparative study of three machine learning methods for software fault prediction
    Wang, Qi
    Zhu, Jie
    Yu, Bo
    [J]. Journal of Shanghai Jiaotong University (Science), 2005, 10 E (02) : 117 - 121
  • [9] A Comparative Study of Three Machine Learning Methods for Software Fault Prediction
    王琪
    朱杰
    于波
    [J]. Journal of Shanghai Jiaotong University(Science), 2005, (02) : 117 - 121
  • [10] Software reliability prediction using machine learning techniques
    Jaiswal A.
    Malhotra R.
    [J]. International Journal of System Assurance Engineering and Management, 2018, 9 (1) : 230 - 244