计算机科学
源代码
调用图
服务拒绝攻击
图形
软件
数据挖掘
测试套件
脆弱性(计算)
理论计算机科学
计算机安全
测试用例
机器学习
程序设计语言
互联网
操作系统
回归分析
作者
Zihan Yu,Jintao Xue,Xin Sun,Wen Wang,Yubo Song,Liquan Chen,Zhongyuan Qin
标识
DOI:10.1109/cis58238.2022.00087
摘要
The increasing number of software vulnerabilities pose serious security attacks and lead to system compromise, information leakage or denial of service. It is a challenge to further improve the vulnerability detection technique. Nowadays most applications are implemented using C/C++. In this paper we focus on the detection of overflow vulnerabilities in C/C++ source code. A novel scheme named VulMiningBGS (Vulnerability Mining Based on Graph Similarity) is proposed. We convert the source code into Top N-Weighted Range Sum Feature Graph (TN-WRSFG), and graph similarity comparisons based on source code level can be effectively carried on to detect possible vulnerabilities. Three categories of vulnerabilities in the Juliet test suite are used, i.e., CWE121, CWE122 and CWE190, with four indicators for performance evaluation (precision, recall, accuracy and F1_score). Experimental results show that our scheme outperforms the traditional methods, and is effective in the overflow vulnerability detection for C/C++ source code.
科研通智能强力驱动
Strongly Powered by AbleSci AI