Security Vulnerability Detection Using Deep Learning Natural Language Processing
Security Vulnerability Detection Using Deep Learning Natural Language Processing
复制标题
DOI:
10.1109/infocomwkshps51825.2021.9484500
复制
发表时间:
2021-05
期刊:
影响因子:
--
通讯作者:
Noah Ziems;Shaoen Wu
中科院分区:
文献类型:
--
作者:
Noah Ziems;Shaoen Wu
Detecting security vulnerabilities in software before they are exploited has been a challenging problem for decades. Traditional code analysis methods have been proposed, but are often ineffective and inefficient. In this work, we model software vulnerability detection as a natural language processing (NLP) problem with source code treated as texts, and address the auto-mated software venerability detection with recent advanced deep learning NLP models assisted by transfer learning on written English. For training and testing, we have preprocessed the NIST NVD/SARD databases and built a dataset of over 100,000 files in C programming language with 123 types of vulnerabilities. The extensive experiments generate the best performance of over 93% accuracy in detecting security vulnerabilities.