Learning to Detect Memory-related Vulnerabilities

计算机科学 语义学(计算机科学) 语法 脆弱性(计算) 背景(考古学) 编码(集合论) 人工智能 机器学习 程序设计语言 计算机安全 生物 古生物学 集合(抽象数据类型)
作者
Sicong Cao,Xiaobing Sun,Lili Bo,Rongxin Wu,Bin Li,Xiaoxue Wu,Chuanqi Tao,Tao Zhang,Wei Liu
出处
期刊:ACM Transactions on Software Engineering and Methodology [Association for Computing Machinery]
卷期号:33 (2): 1-35 被引量:13
标识
DOI:10.1145/3624744
摘要

Memory-related vulnerabilities can result in performance degradation or even program crashes, constituting severe threats to the security of modern software. Despite the promising results of deep learning (DL)-based vulnerability detectors, there exist three main limitations: (1) rich contextual program semantics related to vulnerabilities have not yet been fully modeled; (2) multi-granularity vulnerability features in hierarchical code structure are still hard to be captured; and (3) heterogeneous flow information is not well utilized. To address these limitations, in this article, we propose a novel DL-based approach, called MVD+ , to detect memory-related vulnerabilities at the statement-level. Specifically, it conducts both intraprocedural and interprocedural analysis to model vulnerability features, and adopts a hierarchical representation learning strategy, which performs syntax-aware neural embedding within statements and captures structured context information across statements based on a novel Flow-Sensitive Graph Neural Networks, to learn both syntactic and semantic features of vulnerable code. To demonstrate the performance, we conducted extensive experiments against eight state-of-the-art DL-based approaches as well as five well-known static analyzers on our constructed dataset with 6,879 vulnerabilities in 12 popular C/C++ applications. The experimental results confirmed that MVD+ can significantly outperform current state-of-the-art baselines and make a great trade-off between effectiveness and efficiency.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
1秒前
楼醉山发布了新的文献求助10
2秒前
2秒前
传奇3应助五山第一院士采纳,获得10
2秒前
Zheng完成签到,获得积分10
5秒前
Wenky完成签到 ,获得积分10
5秒前
包包完成签到 ,获得积分10
6秒前
6秒前
6秒前
7秒前
lily发布了新的文献求助10
9秒前
啦啦啦发布了新的文献求助10
10秒前
自由的乐蕊完成签到,获得积分10
11秒前
瘦瘦发布了新的文献求助10
11秒前
minic发布了新的文献求助30
12秒前
希望天下0贩的0应助雨季采纳,获得10
12秒前
13秒前
14秒前
MAVS发布了新的文献求助10
14秒前
Zheng发布了新的文献求助10
14秒前
bkagyin应助科研通管家采纳,获得10
14秒前
无极微光应助科研通管家采纳,获得20
14秒前
打打应助科研通管家采纳,获得10
14秒前
14秒前
14秒前
14秒前
酷波er应助科研通管家采纳,获得10
14秒前
CipherSage应助科研通管家采纳,获得10
15秒前
16秒前
16秒前
crt发布了新的文献求助20
17秒前
17秒前
bthlw发布了新的文献求助10
18秒前
18秒前
XQQDD应助tian采纳,获得20
19秒前
高兴绿柳发布了新的文献求助10
21秒前
雨季发布了新的文献求助10
22秒前
22秒前
buyaoshuo发布了新的文献求助10
22秒前
slby完成签到 ,获得积分10
23秒前
高分求助中
Malcolm Fraser : a biography 680
Signals, Systems, and Signal Processing 610
天津市智库成果选编 600
Climate change and sports: Statistics report on climate change and sports 500
Forced degradation and stability indicating LC method for Letrozole: A stress testing guide 500
全相对论原子结构与含时波包动力学的理论研究--清华大学 500
Organic Reactions Volume 118 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6455450
求助须知:如何正确求助?哪些是违规求助? 8266069
关于积分的说明 17617963
捐赠科研通 5521604
什么是DOI,文献DOI怎么找? 2904927
邀请新用户注册赠送积分活动 1881636
关于科研通互助平台的介绍 1724588