about
A Hierarchical Deep Neural Network for Detecting Code Vulnerabilities (arxiv.org)
1 point by PaulHoule on Nov 17, 2022 | hide | past | pdf | discuss on HN

In plain words: A program's compiled code is treated like text so a deep network can first flag vulnerable code, then point to the lines causing it. This two-step check cut false alarms about which lines are bad, while spotting vulnerable code about 98% of the time.

Abstract · A Hierarchical Deep Neural Network for Detecting Lines of Codes with Vulnerabilities

Software vulnerabilities, caused by unintentional flaws in source codes, are the main root cause of cyberattacks. Source code static analysis has been used extensively to detect the unintentional defects, i.e. vulnerabilities, introduced into the source codes by software developers. In this paper, we propose a deep learning approach to detect vulnerabilities from their LLVM IR representations based on the techniques that have been used in natural language processing. The proposed approach uses a hierarchical process to first identify source codes with vulnerabilities, and then it identifies the lines of codes that contribute to the vulnerability within the detected source codes. This proposed two-step approach reduces the false alarm of detecting vulnerable lines. Our extensive experiment on real-world and synthetic codes collected in NVD and SARD shows high accuracy (about 98\%) in detecting source code vulnerabilities.

Arash Mahyari
arXiv:2211.08517 · cs.CR, cs.AI, cs.LG, cs.PL, cs.SE · submitted Nov 15, 2022
abstract · pdf · html · 22nd IEEE International Conference on Software, Quality, Reliability, and Security (QRS 2022)

add comment on HN