摘要
It has been widely adopted to minimize the maintenance cost by predicting potential vulnerabilities before code audits in academia and industry. Most previous research dedicated to file/component level vulnerability prediction models is coarse- grained and may suffer from cost-prohibitive and impractical security testing activities. In this paper, we focus on a cost- aware vulnerability prediction model and present a just-in-time change-level code review tool called VulDigger to dig suspicious ones from a sea of code changes. Our contributions benefit from the case study of Mozilla Firefox by constructing a large-scale vulnerability-contributing changes (VCCs) dataset in a semi-automatic fashion. We then further manifest a classification tool with a mixture of established and new metrics derived from both software defect prediction and vulnerability prediction. Consequently, the precision of such tool is extremely promising (i.e., 92%) for an effort-aware software team. We also examine the return on investment by training a regression model to locate most skeptical changes with fewer lines to inspect. Our findings suggest that such model is capable of pinpointing 31% of all VCCs with only 20% of the effort it would take to audit all changes (i.e., 55% better than random predictor). Our outputs can assist as an early step of continuous security inspections as it provides immediate feedback once developers submit changes to their code base.
| 源语言 | 英语 |
|---|---|
| 文章编号 | 8254428 |
| 页(从-至) | 1-7 |
| 页数 | 7 |
| 期刊 | Proceedings - IEEE Global Communications Conference, GLOBECOM |
| 卷 | 2018-January |
| DOI | |
| 出版状态 | 已出版 - 2017 |
| 活动 | 2017 IEEE Global Communications Conference, GLOBECOM 2017 - Singapore, 新加坡 期限: 4 12月 2017 → 8 12月 2017 |
指纹
探究 'VulDigger: A Just-in-Time and Cost-Aware Tool for Digging Vulnerability-Contributing Changes' 的科研主题。它们共同构成独一无二的指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver