Detection of Software Vulnerabilities using Machine Learning
Detection of Software Vulnerabilities using Machine Learning
批准号:
242913835
负责人:
Professor Dr. Konrad Rieck
金额:
$0.0万
依托单位国家:
德国
项目类别:
Research Grants
财政年份:
2014
资助国家:
德国
项目状态:
已结题
起止时间:
2013-12-31 至 2016-12-31
中文摘要
早期发现软件漏洞是保证计算机系统安全的关键。虽然某些类型的安全漏洞可以自动识别,但大多数漏洞仍然是通过耗时的手动分析发现的。该项目旨在利用机器学习技术开发新的漏洞发现方法。为此,代码的结构化表示,如解析树和控制流图,被嵌入到向量空间中,并使用无监督学习算法进行语义分析和异常检测。这种分析应该能够自动识别典型的编程模式,并检测偏离这些模式的潜在漏洞。
英文摘要
The early detection of vulnerabilities in software is a key for securing computer systems. While some types of security flaws can be identified automatically, the majority of vulnerabilities is still discovered by time-consuming manual analysis. This project aims at developing novel methods for vulnerability discovery using machine learning techniques. To this end, structured representations of code, such as parse trees and control flow graphs, are embedded in vector spaces and analyzed using unsupervised learning algorithms for semantic analysis and anomaly detection. This analysis should enable identifying typical programming patterns automatically and detecting potential vulnerabilities as deviations from these patterns.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/2976749.2978403
发表时间:
2016-10
期刊:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Christian Wressnegger;Fabian Yamaguchi;Alwin Maier;Konrad Rieck]
通讯作者:
Christian Wressnegger;Fabian Yamaguchi;Alwin Maier;Konrad Rieck
DOI:
10.1109/sp.2015.54
发表时间:
2015
期刊:
2015 IEEE Symposium on Security and Privacy
影响因子:
--
作者:
[F. Yamaguchi, A. Maier, H. Gascon, K. Rieck]
通讯作者:
K. Rieck
DOI:
10.1145/2508859.2516665
发表时间:
2013-11
期刊:
Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security
影响因子:
--
作者:
[Fabian Yamaguchi;Christian Wressnegger;Hugo Gascon;Konrad Rieck]
通讯作者:
Fabian Yamaguchi;Christian Wressnegger;Hugo Gascon;Konrad Rieck
Machine Learning and Digital Watermarking in Adversarial Environments
-
批准号:393063728
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:2017
-
负责人:Professor Dr. Konrad Rieck
-
依托单位:
Attacks against Machine Learning in Structured Domains
-
批准号:492020528
-
项目类别:Research Grants
-
资助金额:$0.0万
-
财政年份:--
-
负责人:Professor Dr. Konrad Rieck
-
依托单位:
海外基金