已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

UltraVCS: Ultra-Fine-Grained Variable-Based Code Slicing for Automated Vulnerability Detection

计算机科学 程序切片 切片 变量(数学) 脆弱性(计算) 编码(集合论) 程序设计语言 计算机安全 计算机图形学(图像) 集合(抽象数据类型) 数学 数学分析
作者
Tongshuai Wu,Liwei Chen,Gewangzi Du,Dan Meng,Gang Shi
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 3986-4000 被引量:19
标识
DOI:10.1109/tifs.2024.3374219
摘要

Detecting vulnerabilities in source code using deep learning models is emerging as a valuable research area. The key issue in using deep learning to detect vulnerabilities is the accurate representation. Current approaches for detecting vulnerabilities in C/C++ programs use functions or lines of code as the unit and only consider the basic syntactic structure of vulnerabilities. Unfortunately, functions and lines of code still have vulnerability-unrelated information, which is redundant for vulnerability features and is not conducive to deep learning models to learn accurate vulnerability patterns. This paper deeply analyzes the essential features of vulnerabilities and attacks. Then, we propose a novel variable-based deep learning vulnerability detection method for C/C++ that is more granular than existing function- or line of code-based vulnerability detection methods. Based on the triggering mechanism of vulnerabilities and typical memory attacks, we propose the concepts of key variables and insecure operations; these are used to propose new rules for determining the center point of code slices with more accurate vulnerability features. We propose the first ultra-fine-grained variable-based code slicing (UltraVCS) method by the new center point, which focuses on the vulnerability-related variable. This method removes as much vulnerability-unrelated information as possible to achieve more accurate vulnerability feature extraction. Experiments show that our approach can generate more code slices, achieve more precise vulnerability representation, and perform better vulnerability detection in open-source projects compared to state-of-the-art methods. Furthermore, we have discovered four zero-day vulnerabilities in real-world application scenarios in open-source projects.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
1秒前
4秒前
深情安青应助快乐的绿柳采纳,获得10
5秒前
LiuKangwei完成签到,获得积分10
5秒前
7秒前
慈祥的雪冥完成签到 ,获得积分10
8秒前
8秒前
科研通AI6.3应助温简采纳,获得10
10秒前
11秒前
王皮皮完成签到 ,获得积分10
13秒前
孤独的图图完成签到,获得积分10
14秒前
黎黎发布了新的文献求助10
14秒前
八百标兵发布了新的文献求助10
14秒前
yeguo完成签到,获得积分20
14秒前
欢呼金鱼发布了新的文献求助10
14秒前
15秒前
16秒前
19秒前
沫沫沫沫发布了新的文献求助10
19秒前
大模型应助雁青采纳,获得30
19秒前
热情的访枫完成签到 ,获得积分10
19秒前
20秒前
Hero发布了新的文献求助10
21秒前
22秒前
Spike完成签到 ,获得积分10
23秒前
小肉包脸完成签到 ,获得积分10
24秒前
lzn完成签到,获得积分10
24秒前
露露露发布了新的文献求助10
25秒前
fancycow完成签到,获得积分10
27秒前
wxx发布了新的文献求助10
27秒前
荷包蛋没你可爱完成签到 ,获得积分10
28秒前
共享精神应助green采纳,获得10
29秒前
vetzlk完成签到 ,获得积分10
29秒前
黎黎发布了新的文献求助10
29秒前
29秒前
温简发布了新的文献求助10
31秒前
32秒前
33秒前
科研通AI6.2应助李嘉怡采纳,获得10
34秒前
Orange应助liqin采纳,获得10
34秒前
高分求助中
Markov Chain Monte Carlo 10000
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Common Foundations of American and East Asian Modernisation: From Alexander Hamilton to Junichero Koizumi 5000
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
Discerning Saints: Moralization of Intrinsic Motivation and Selective Prosociality at Work 500
Handbuch Trainingswissenschaft – Trainingslehre 500
Additive Manufacturing Design and Applications (ASM Handbook, Volume 24A) 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7584873
求助须知:如何正确求助?哪些是违规求助? 9163378
关于积分的说明 19610743
捐赠科研通 7166556
什么是DOI,文献DOI怎么找? 3266554
关于科研通互助平台的介绍 2431552
邀请新用户注册赠送积分活动 2258219