A Comparative Study of Deep Learning-Based Vulnerability Detection System

计算机科学 脆弱性(计算) 人工智能 深度学习 机器学习 卷积神经网络 循环神经网络 假阳性率 依赖关系(UML) 数据挖掘 人工神经网络 计算机安全
作者
Zhen Li,Deqing Zou,Jing Tang,Zhihao Zhang,Mucun Sun,Hai Jin
出处
期刊:IEEE Access [Institute of Electrical and Electronics Engineers]
卷期号:7: 103184-103197 被引量:62
标识
DOI:10.1109/access.2019.2930578
摘要

Source code static analysis has been widely used to detect vulnerabilities in the development of software products. The vulnerability patterns purely based on human experts are laborious and error prone, which has motivated the use of machine learning for vulnerability detection. In order to relieve human experts of defining vulnerability rules or features, a recent study shows the feasibility of leveraging deep learning to detect vulnerabilities automatically. However, the impact of different factors on the effectiveness of vulnerability detection is unknown. In this paper, we collect two datasets from the programs involving 126 types of vulnerabilities, on which we conduct the first comparative study to quantitatively evaluate the impact of different factors on the effectiveness of vulnerability detection. The experimental results show that accommodating control dependency can increase the overall effectiveness of vulnerability detection F1-measure by 20.3%; the imbalanced data processing methods are not effective for the dataset we create; bidirectional recurrent neural networks (RNNs) are more effective than unidirectional RNNs and convolutional neural network, which in turn are more effective than multi-layer perception; using the last output corresponding to the time step for the bidirectional long short-term memory (BLSTM) can reduce the false negative rate by 2.0% at the price of increasing the false positive rate by 0.5%.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
1秒前
2秒前
翁依波发布了新的文献求助10
2秒前
2秒前
2秒前
小二郎应助文静的觅海采纳,获得10
3秒前
4秒前
阿萌毛毛发布了新的文献求助10
5秒前
7秒前
琪琪发布了新的文献求助10
7秒前
7秒前
小丫丫完成签到,获得积分10
10秒前
烟花应助眯眯眼的不斜采纳,获得10
10秒前
10秒前
11秒前
123hu发布了新的文献求助10
11秒前
小孔007完成签到,获得积分10
11秒前
文天烽完成签到,获得积分10
13秒前
14秒前
刘_Young发布了新的文献求助10
14秒前
lihua发布了新的文献求助10
15秒前
玛卡巴卡完成签到,获得积分10
15秒前
Ava应助张震采纳,获得10
15秒前
16秒前
玛卡巴卡发布了新的文献求助10
19秒前
19秒前
酷波er应助尔东采纳,获得10
23秒前
大个应助莉莉子采纳,获得10
24秒前
25秒前
26秒前
隐形曼青应助玛卡巴卡采纳,获得10
26秒前
26秒前
27秒前
高高完成签到 ,获得积分10
28秒前
搜集达人应助123采纳,获得10
29秒前
Owen应助秃顶双马尾采纳,获得10
30秒前
30秒前
31秒前
大模型应助文静的觅海采纳,获得10
31秒前
高分求助中
Teaching Social and Emotional Learning in Physical Education 900
Plesiosaur extinction cycles; events that mark the beginning, middle and end of the Cretaceous 500
Chinese-English Translation Lexicon Version 3.0 500
[Lambert-Eaton syndrome without calcium channel autoantibodies] 440
Two-sample Mendelian randomization analysis reveals causal relationships between blood lipids and venous thromboembolism 400
薩提亞模式團體方案對青年情侶輔導效果之研究 400
3X3 Basketball: Everything You Need to Know 310
热门求助领域 (近24小时)
化学 材料科学 医学 生物 有机化学 工程类 生物化学 纳米技术 物理 内科学 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 电极 光电子学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 2386987
求助须知:如何正确求助?哪些是违规求助? 2093452
关于积分的说明 5268082
捐赠科研通 1820116
什么是DOI,文献DOI怎么找? 907987
版权声明 559236
科研通“疑难数据库(出版商)”最低求助积分说明 484991