A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
批准号:
RGPIN-2018-05931
负责人:
Lie, David
金额:
$2.04万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2018
资助国家:
加拿大
项目状态:
已结题
起止时间:
2018-01-01 至 2019-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
This proposal aims to explore a new way of detecting software vulnerabilities using a novel combination of program analysis, dynamic test generation and machine learning. Currently, one of the most reliable methods for detecting software vulnerabilities is source code audits, where a developer manually inspects the source code of a program to see if vulnerabilities are present. Unfortunately, software systems are large, commonly containing tens of millions of lines of code, making it an impossible task to secure all software through manual code audits. In this proposal, we explore a better way to detect software vulnerabilities--by developing machine learning methods that will identify software vulnerabilities.******The key to enabling machine learning to outperform existing vulnerability detection tools is to recognize that there are common programming patterns, embedded in the structure of code, as well as in the names of variables and functions, that can indicate the presence of a vulnerability, but for which there exists no explicit specification. Current solutions that try to mechanize the scanning of code for vulnerabilities all rely only on what is explicitly specified by the programming language or application binary interface (ABI), and do not take these implicit code patterns into account. Some tools do allow a human to hand-specify vulnerability patterns to overcome this limitation, but the huge variation in vulnerability patterns means that even with these specifications, many vulnerabilities will be missed by automated vulnerability detection tools. The key novel approach in this proposal is to use machine learning to automatically learn and utilize programming patterns, embedded in code structure and variable names, that indicate the presence of a vulnerability and use this to automatically detect vulnerabilities in software with high accuracy.******We acknowledge that the capabilities of such machine-learning inference may not be completely accurate, and more likely will just indicate code that is very likely vulnerable. To make ensure the identified vulnerabilities are real, we propose combining the inference results with fuzzing, a dynamic testing method that searches for inputs that trigger vulnerabilities. Fuzzers are very effective at triggering vulnerabilities, but they have a critical weakness, which is that they must execute the vulnerable code to detect it, and without a guide to where that code might be, they are forced to generate inputs to execute every code path in a program, which is not only inefficient, but often intractable. We propose the development of new targeted fuzzers, which use hints from our machine learning to select sections of code to focus on, thus increasing the efficiency of fuzzing. Triggering the vulnerability gives unequivocal proof that the vulnerability exists, complementing the inherent imprecision of machine learning
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
-
批准号:RGPIN-2018-05931
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2022
-
负责人:Lie, David
-
依托单位:
Secure and Reliable Systems
-
批准号:CRC-2019-00242
-
项目类别:Canada Research Chairs
-
资助金额:$14.57万
-
财政年份:2022
-
负责人:Lie, David
-
依托单位:
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
-
批准号:RGPIN-2018-05931
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2021
-
负责人:Lie, David
-
依托单位:
Tools and methods for detecting vulnerabilities in embedded devices
-
批准号:535902-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$5.19万
-
财政年份:2021
-
负责人:Lie, David
-
依托单位:
Mitigating Software Vulnerabilities with Architectural Support for Type-safety
-
批准号:541942-2019
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$12.76万
-
财政年份:2021
-
负责人:Lie, David
-
依托单位:
Secure And Reliable Systems
-
批准号:CRC-2019-00242
-
项目类别:Canada Research Chairs
-
资助金额:$14.57万
-
财政年份:2021
-
负责人:Lie, David
-
依托单位:
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
-
批准号:RGPIN-2018-05931
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2020
-
负责人:Lie, David
-
依托单位:
Mitigating Software Vulnerabilities with Architectural Support for Type-safety
-
批准号:541942-2019
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$12.76万
-
财政年份:2020
-
负责人:Lie, David
-
依托单位:
Secure and Reliable Systems
-
批准号:CRC-2019-00242
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2020
-
负责人:Lie, David
-
依托单位:
Tools and methods for detecting vulnerabilities in embedded devices
-
批准号:535902-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$5.19万
-
财政年份:2020
-
负责人:Lie, David
-
依托单位:
Tools and methods for detecting vulnerabilities in embedded devices
-
批准号:535902-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$5.19万
-
财政年份:2019
-
负责人:Lie, David
-
依托单位:
A Machine Learning Approach to Detecting Security Vulnerabilities in Software.
-
批准号:RGPIN-2018-05931
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2019
-
负责人:Lie, David
-
依托单位:
Mitigating Software Vulnerabilities with Architectural Support for Type-safety
-
批准号:541942-2019
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$6.73万
-
财政年份:2019
-
负责人:Lie, David
-
依托单位:
Computational tools for analyzing and detecting software supply chain attacks
-
批准号:474601-2014
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$5.1万
-
财政年份:2017
-
负责人:Lie, David
-
依托单位:
Secure and Reliable Computer Systems
-
批准号:1000228402-2012
-
项目类别:Canada Research Chairs
-
资助金额:$3.64万
-
财政年份:2017
-
负责人:Lie, David
-
依托单位:
An Information Flow Approach to Data Security
-
批准号:293209-2013
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2017
-
负责人:Lie, David
-
依托单位:
Computational tools for analyzing and detecting software supply chain attacks
-
批准号:474601-2014
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$5.1万
-
财政年份:2016
-
负责人:Lie, David
-
依托单位:
Secure and Reliable Computer Systems
-
批准号:1000228402-2012
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2016
-
负责人:Lie, David
-
依托单位:
An Information Flow Approach to Data Security
-
批准号:293209-2013
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.19万
-
财政年份:2015
-
负责人:Lie, David
-
依托单位:
Secure and Reliable Computer Systems
-
批准号:1228402-2012
-
项目类别:Canada Research Chairs
-
资助金额:$7.29万
-
财政年份:2015
-
负责人:Lie, David
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
-
批准号:--
-
项目类别:合作创新研究团队
-
资助金额:--
-
批准年份:2024
-
负责人:姚韬
-
依托单位:
Understanding structural evolution of galaxies with machine learning
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:Nicola Rosario Napolitano
-
依托单位:
煤矿安全人机混合群智感知任务的约束动态多目标Q-learning进化分配
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:吉建娇
-
依托单位:
基于领弹失效考量的智能弹药编队短时在线Q-learning协同控制机理
-
批准号:62003314
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:沈剑
-
依托单位:
集成上下文张量分解的e-learning资源推荐方法研究
-
批准号:61902016
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2019
-
负责人:万珊珊
-
依托单位:
具有时序迁移能力的Spiking-Transfer learning (脉冲-迁移学习)方法研究
-
批准号:61806040
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2018
-
负责人:解修蕊
-
依托单位:
基于Deep-learning的三江源区冰川监测动态识别技术研究
-
批准号:51769027
-
项目类别:地区科学基金项目
-
资助金额:38.0万元
-
批准年份:2017
-
负责人:张大奇
-
依托单位:
具有时序处理能力的Spiking-Deep Learning(脉冲深度学习)方法研究
-
批准号:61573081
-
项目类别:面上项目
-
资助金额:64.0万元
-
批准年份:2015
-
负责人:屈鸿
-
依托单位:
基于有向超图的大型个性化e-learning学习过程模型的自动生成与优化
-
批准号:61572533
-
项目类别:面上项目
-
资助金额:66.0万元
-
批准年份:2015
-
负责人:孙雪冬
-
依托单位:
E-Learning中学习者情感补偿方法的研究
-
批准号:61402392
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2014
-
负责人:秦继伟
-
依托单位: