about
End to End Prediction of Buffer Overruns from Code via Neural Memory Networks (arxiv.org)
39 points by DanielRibeiro on Mar 20, 2017 | hide | past | pdf | 4 comments on HN

In plain words: A system reads source code as plain text, stores clues in a memory it can reread, and says whether a buffer overrun is present. It caught simple overruns accurately and learned to track variables and compare numbers, unlike checkers that need hand-written bug patterns.

Abstract · End-to-End Prediction of Buffer Overruns from Raw Source Code via Neural Memory Networks

Detecting buffer overruns from a source code is one of the most common and yet challenging tasks in program analysis. Current approaches have mainly relied on rigid rules and handcrafted features devised by a few experts, limiting themselves in terms of flexible applicability and robustness due to diverse bug patterns and characteristics existing in sophisticated real-world software programs. In this paper, we propose a novel, data-driven approach that is completely end-to-end without requiring any hand-crafted features, thus free from any program language-specific structural limitations. In particular, our approach leverages a recently proposed neural network model called memory networks that have shown the state-of-the-art performances mainly in question-answering tasks. Our experimental results using source codes demonstrate that our proposed model is capable of accurately detecting simple buffer overruns. We also present in-depth analyses on how a memory network can learn to understand the semantics in programming languages solely from raw source codes, such as tracing variables of interest, identifying numerical values, and performing their quantitative comparisons.

Min-je Choi, Sehun Jeong, Hakjoo Oh, Jaegul Choo
arXiv:1703.02458 · cs.SE, cs.NE · submitted Mar 7, 2017
abstract · pdf · html · 6 pages + 1 appendix, 5 figures

add comment on HN

This is really cool. I've spent some time thinking about a similar idea in the past [0].

My idea was to parse the CVE database for bugs in open source code, then identify the patches used to fix the bugs. From the patch data, you can get an efficient diff of what the "vulnerable" code looks like and what the "fix" for it looks like. You can then convert the code to abstract syntax tree or feed it to a static analysis engine to use as "signals" in training a machine learning algorithm. Then you can apply the machine learning algorithm to open source databases and identify possibly vulnerable code paths.

Looks like this paper had success doing something similar. Awesome!

[0] https://news.ycombinator.com/item?id=11573547

The first thing it learns is to check if the source is in Rust and if so, vastly reduce the likelihood of a buffer overrun.
Groan. Rust fanboy here, but c'mon. Are you a member of the "Rust Evangelism Strikeforce" (as seen at http://n-gate.com/)?
Rust is a great thing, and by reducing the number of faults that need to be searched for, it would actually help this kind of AI do its thing, here, too. But Rust doesn't prevent every problem, and sometimes ya gotta go unsafe in Rust, at which point it would be nice to have a quick check on that code. So I think these are independent endeavors; both very worthy.