亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

BGNN4VD: Constructing Bidirectional Graph Neural-Network for Vulnerability Detection

计算机科学 深度学习 人工智能 源代码 图形 卷积神经网络 控制流程图 分类器(UML) 人工神经网络 编码(集合论) 脆弱性(计算) 抽象语法树 机器学习 数据挖掘 抽象语法 模式识别(心理学) 语法 理论计算机科学 程序设计语言 集合(抽象数据类型) 计算机安全
作者
Sicong Cao,Xiaobing Sun,Lili Bo,Weiqin Ying,Bin Li
出处
期刊:Information & Software Technology [Elsevier BV]
卷期号:136: 106576-106576 被引量:158
标识
DOI:10.1016/j.infsof.2021.106576
摘要

Previous studies have shown that existing deep learning-based approaches can significantly improve the performance of vulnerability detection. They represent code in various forms and mine vulnerability features with deep learning models. However, the differences of code representation forms and deep learning models make various approaches still have some limitations. In practice, their false-positive rate (FPR) and false-negative rate (FNR) are still high. To address the limitations of existing deep learning-based vulnerability detection approaches, we propose BGNN4VD (Bidirectional Graph Neural Network for Vulnerability Detection), a vulnerability detection approach by constructing a Bidirectional Graph Neural-Network (BGNN). In Phase 1, we extract the syntax and semantic information of source code through abstract syntax tree (AST), control flow graph (CFG), and data flow graph (DFG). Then in Phase 2, we use vectorized source code as input to Bidirectional Graph Neural-Network (BGNN). In Phase 3, we learn the different features between vulnerable code and non-vulnerable code by introducing backward edges on the basis of traditional Graph Neural-Network (GNN). Finally in Phase 4, a Convolutional Neural-Network (CNN) is used to further extract features and detect vulnerabilities through a classifier. We evaluate BGNN4VD on four popular C/C++ projects from NVD and GitHub, and compare it with four state-of-the-art (Flawfinder, RATS, SySeVR, and VUDDY) vulnerab ility detection approaches. Experiment results show that, when compared these baselines, BGNN4VD achieves 4.9%, 11.0%, and 8.4% improvement in F1-measure, accuracy and precision, respectively. The proposed BGNN4VD achieves a higher precision and accuracy than the state-of-the-art methods. In addition, when applied on the latest vulnerabilities reported by CVE, BGNN4VD can still achieve a precision at 45.1%, which demonstrates the feasibility of BGNN4VD in practical application.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
OsamaKareem应助li采纳,获得10
1秒前
打打应助林黛玉采纳,获得10
7秒前
12秒前
16秒前
Kaleido发布了新的文献求助10
17秒前
人抗破伤风免疫球蛋白完成签到,获得积分10
19秒前
林黛玉发布了新的文献求助10
20秒前
Kaleido完成签到,获得积分20
23秒前
29秒前
31秒前
36秒前
sora98完成签到 ,获得积分10
37秒前
xingsixs完成签到 ,获得积分10
42秒前
43秒前
研友_VZG7GZ应助舒克采纳,获得10
46秒前
55秒前
今后应助酷炫的项链采纳,获得10
1分钟前
lxl发布了新的文献求助10
1分钟前
忐忑的烤鸡发布了新的文献求助100
1分钟前
大个应助lxl采纳,获得10
1分钟前
小菜完成签到,获得积分10
1分钟前
DDF完成签到 ,获得积分10
1分钟前
忐忑的烤鸡完成签到,获得积分10
1分钟前
Orange应助Lavender采纳,获得10
1分钟前
1分钟前
2分钟前
陳.发布了新的文献求助10
2分钟前
高贵曼冬发布了新的文献求助10
2分钟前
2分钟前
Lavender发布了新的文献求助10
2分钟前
酷炫的项链完成签到,获得积分10
2分钟前
2分钟前
2分钟前
2分钟前
lxl发布了新的文献求助10
2分钟前
2分钟前
2分钟前
efig完成签到 ,获得积分10
2分钟前
陳.完成签到 ,获得积分20
2分钟前
英姑应助酷炫的项链采纳,获得10
2分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Chemistry and Physics of Carbon Volume 18 800
The Organometallic Chemistry of the Transition Metals 800
The formation of Australian attitudes towards China, 1918-1941 640
Signals, Systems, and Signal Processing 610
Development Across Adulthood 600
天津市智库成果选编 600
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6444342
求助须知:如何正确求助?哪些是违规求助? 8258249
关于积分的说明 17590968
捐赠科研通 5503427
什么是DOI,文献DOI怎么找? 2901326
邀请新用户注册赠送积分活动 1878371
关于科研通互助平台的介绍 1717663