亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

BGNN4VD: Constructing Bidirectional Graph Neural-Network for Vulnerability Detection

计算机科学 深度学习 人工智能 源代码 图形 卷积神经网络 控制流程图 分类器(UML) 人工神经网络 编码(集合论) 脆弱性(计算) 抽象语法树 机器学习 数据挖掘 抽象语法 模式识别(心理学) 语法 理论计算机科学 程序设计语言 集合(抽象数据类型) 计算机安全
作者
Sicong Cao,Xiaobing Sun,Lili Bo,Weiqin Ying,Bin Li
出处
期刊:Information & Software Technology [Elsevier BV]
卷期号:136: 106576-106576 被引量:158
标识
DOI:10.1016/j.infsof.2021.106576
摘要

Previous studies have shown that existing deep learning-based approaches can significantly improve the performance of vulnerability detection. They represent code in various forms and mine vulnerability features with deep learning models. However, the differences of code representation forms and deep learning models make various approaches still have some limitations. In practice, their false-positive rate (FPR) and false-negative rate (FNR) are still high. To address the limitations of existing deep learning-based vulnerability detection approaches, we propose BGNN4VD (Bidirectional Graph Neural Network for Vulnerability Detection), a vulnerability detection approach by constructing a Bidirectional Graph Neural-Network (BGNN). In Phase 1, we extract the syntax and semantic information of source code through abstract syntax tree (AST), control flow graph (CFG), and data flow graph (DFG). Then in Phase 2, we use vectorized source code as input to Bidirectional Graph Neural-Network (BGNN). In Phase 3, we learn the different features between vulnerable code and non-vulnerable code by introducing backward edges on the basis of traditional Graph Neural-Network (GNN). Finally in Phase 4, a Convolutional Neural-Network (CNN) is used to further extract features and detect vulnerabilities through a classifier. We evaluate BGNN4VD on four popular C/C++ projects from NVD and GitHub, and compare it with four state-of-the-art (Flawfinder, RATS, SySeVR, and VUDDY) vulnerab ility detection approaches. Experiment results show that, when compared these baselines, BGNN4VD achieves 4.9%, 11.0%, and 8.4% improvement in F1-measure, accuracy and precision, respectively. The proposed BGNN4VD achieves a higher precision and accuracy than the state-of-the-art methods. In addition, when applied on the latest vulnerabilities reported by CVE, BGNN4VD can still achieve a precision at 45.1%, which demonstrates the feasibility of BGNN4VD in practical application.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
hhuajw发布了新的文献求助200
33秒前
ff完成签到 ,获得积分10
59秒前
1分钟前
科研通AI2S应助科研通管家采纳,获得10
1分钟前
ziyu完成签到,获得积分10
1分钟前
yookia应助葛力采纳,获得10
1分钟前
1分钟前
充电宝应助Li采纳,获得10
1分钟前
猪猪完成签到 ,获得积分10
2分钟前
2分钟前
2分钟前
2分钟前
Li发布了新的文献求助10
2分钟前
2分钟前
fm2m发布了新的文献求助30
2分钟前
2分钟前
Ava应助fm2m采纳,获得10
3分钟前
阿胡完成签到 ,获得积分20
3分钟前
fm2m完成签到,获得积分10
3分钟前
3分钟前
miles完成签到,获得积分10
3分钟前
归尘发布了新的文献求助10
3分钟前
SciGPT应助一个科研人采纳,获得10
4分钟前
4分钟前
热情的觅云完成签到 ,获得积分10
4分钟前
4分钟前
4分钟前
5分钟前
5分钟前
Migue发布了新的文献求助30
5分钟前
上官若男应助一个科研人采纳,获得10
7分钟前
7分钟前
7分钟前
8分钟前
8分钟前
Yuki完成签到 ,获得积分10
8分钟前
肥猫发布了新的文献求助10
8分钟前
8分钟前
Migue发布了新的文献求助10
8分钟前
浚稚完成签到 ,获得积分10
8分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Introduction to Helicopter and Tiltrotor Flight Simulation, Second Edition 2500
卤化钙钛矿人工突触的研究 2000
Malcolm Fraser : a biography 700
Signals, Systems, and Signal Processing 610
Software that combines deep learning,3D reconstruction and CFD to analyze the state of carotid arteries from ultrasound imaging 600
Bounds for Statistical Estimation in Semiparametric Models 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6496355
求助须知:如何正确求助?哪些是违规求助? 8292916
关于积分的说明 17695306
捐赠科研通 5590873
什么是DOI,文献DOI怎么找? 2916825
邀请新用户注册赠送积分活动 1893772
关于科研通互助平台的介绍 1753528