Multiclass Classification of Software Vulnerabilities with Deep Learning

Multiclass Classification of Software Vulnerabilities with Deep Learning
复制标题

DOI:
10.1145/3587716.3587738
复制
发表时间:
2023-02
期刊:
Proceedings of the 2023 15th International Conference on Machine Learning and Computing
影响因子:
--
通讯作者:
Crystal Contreras;Hristina Dokic;Zhen Huang;Daniela Stan Raicu;Jacob D. Furst;Roselyne B. Tchoua
Crystal Contreras;Hristina Dokic;Zhen Huang;Daniela Stan Raicu;Jacob D. Furst;Roselyne B. Tchoua
中科院分区:
其他
文献类型:
--
作者:
Crystal Contreras;Hristina Dokic;Zhen Huang;Daniela Stan Raicu;Jacob D. Furst;Roselyne B. Tchoua

文献摘要

相似文献

几十年来,检测软件漏洞一直是一个挑战。已经开发了许多技术来通过报告软件守则中是否存在漏洞来检测漏洞。但是,很少有人能够对检测到的漏洞的类型进行分类,这对于人类开发人员或其他工具至关重要,可以分析和解决漏洞。在本文中,我们介绍了使用深度学习来识别漏洞类型的工作。我们的数据包括以捕获漏洞的语法和语义的方式解析的代码切片,该漏洞是从先前工作中提出的。我们在这些功能上训练深层神经网络,以对数据集中的软件漏洞进行多类分类。我们的实验表明,我们的模型可以有效地识别数据集中脆弱功能的漏洞类别。
Detecting software vulnerabilities has been a challenge for decades. Many techniques have been developed to detect vulnerabilities by reporting whether a vulnerability exists in the code of software. But few of them have the capability to categorize the types of detected vulnerabilities, which is crucial for human developers or other tools to analyze and address vulnerabilities. In this paper, we present our work on identifying the types of vulnerabilities using deep learning. Our data consists of code slices parsed in a manner that captures the syntax and semantics of a vulnerability, sourced from prior work. We train deep neural networks on these features to perform multiclass classification of software vulnerabilities in the dataset. Our experiments show that our models can effectively identify the vulnerability classes of the vulnerable functions in our dataset.