The Experts below are selected from a list of 210 Experts worldwide ranked by ideXlab platform
Zhiyong Feng - One of the best experts on this subject based on the ideXlab platform.
-
DeepWeak: Reasoning common software weaknesses via knowledge graph embedding
2018 IEEE 25th International Conference on Software Analysis Evolution and Reengineering (SANER), 2018Co-Authors: Xiaohong Li, Zhenchang Xing, Zhiyong FengAbstract:common software weaknesses, such as improper input validation, integer overflow, can harm system security directly or indirectly, causing adverse effects such as denial-of-service, execution of unauthorized code. common weakness enumeration (CWE) maintains a standard list and classification of common software weakness. Although CWE contains rich information about software weaknesses, including textual descriptions, common sequences and relations between software weaknesses, the current data representation, i.e., hyperlined documents, does not support advanced reasoning tasks on software weaknesses, such as prediction of missing relations and common consequences of CWEs. Such reasoning tasks become critical to managing and analyzing large numbers of common software weaknesses and their relations. In this paper, we propose to represent common software weaknesses and their relations as a knowledge graph, and develop a translation-based, description-embodied knowledge representation learning method to embed both software weaknesses and their relations in the knowledge graph into a semantic vector space. The vector representations (i.e., embeddings) of software weaknesses and their relations can be exploited for knowledge acquisition and inference. We conduct extensive experiments to evaluate the performance of software weakness and relation embeddings in three reasoning tasks, including CWE link prediction, CWE triple classification, and common consequence prediction. Our knowledge graph embedding approach outperforms other description- and/or structure-based representation learning methods.
-
SANER - DeepWeak: Reasoning common software weaknesses via knowledge graph embedding
2018 IEEE 25th International Conference on Software Analysis Evolution and Reengineering (SANER), 2018Co-Authors: Xiaohong Li, Zhenchang Xing, Zhiyong FengAbstract:common software weaknesses, such as improper input validation, integer overflow, can harm system security directly or indirectly, causing adverse effects such as denial-of-service, execution of unauthorized code. common weakness enumeration (CWE) maintains a standard list and classification of common software weakness. Although CWE contains rich information about software weaknesses, including textual descriptions, common sequences and relations between software weaknesses, the current data representation, i.e., hyperlined documents, does not support advanced reasoning tasks on software weaknesses, such as prediction of missing relations and common consequences of CWEs. Such reasoning tasks become critical to managing and analyzing large numbers of common software weaknesses and their relations. In this paper, we propose to represent common software weaknesses and their relations as a knowledge graph, and develop a translation-based, description-embodied knowledge representation learning method to embed both software weaknesses and their relations in the knowledge graph into a semantic vector space. The vector representations (i.e., embeddings) of software weaknesses and their relations can be exploited for knowledge acquisition and inference. We conduct extensive experiments to evaluate the performance of software weakness and relation embeddings in three reasoning tasks, including CWE link prediction, CWE triple classification, and common consequence prediction. Our knowledge graph embedding approach outperforms other description- and/or structure-based representation learning methods.
-
ICECCS - OOPN-SRAM: A Novel Method for Software Risk Assessment
2014 19th International Conference on Engineering of Complex Computer Systems, 2014Co-Authors: Xiaofei Wu, Xiaohong Li, Ruitao Feng, Guangquan Xu, Jing Hu, Zhiyong FengAbstract:This paper proposes a Software Risk Assessment Method based on Object-Oriented Petri Net (OOPN-SRAM), in which risk assessment procedure is divided into four steps, expressed as four corresponding objects, including asset recognition, weakness analysis, consequence property confirmation and risk calculation. Each object is modeled with Petri net. Specialists recognize software assets by the 1-9 scales method of Analytic Hierarchy Process (AHP). The weaknesses in a system are found by the vulnerability scanner. The damage degree and the exploitation likelihood of a weakness are evaluated by such authorities as common weakness enumeration (CWE). The consequence properties are confirmed by specialists according to the software requirements. Finally, in the risk calculation, risk degree and overall risk value are calculated by using exponential method and weighted average method respectively. Furthermore, we illustrate the application of our OOPN-SRAM method with realistic examples including web-banking and forum, and make a comparison with traditional methods. The results show that OOPN-SRAM not only increases the efficiency of the evaluation process, but also makes the evaluation result more objective and accurate.
-
OOPN-SRAM: A Novel Method for Software Risk Assessment
2014 19th International Conference on Engineering of Complex Computer Systems, 2014Co-Authors: Xiaofei Wu, Xiaohong Li, Ruitao Feng, Guangquan Xu, Jing Hu, Zhiyong FengAbstract:This paper proposes a Software Risk Assessment Method based on Object-Oriented Petri Net (OOPN-SRAM), in which risk assessment procedure is divided into four steps, expressed as four corresponding objects, including asset recognition, weakness analysis, consequence property confirmation and risk calculation. Each object is modeled with Petri net. Specialists recognize software assets by the 1-9 scales method of Analytic Hierarchy Process (AHP). The weaknesses in a system are found by the vulnerability scanner. The damage degree and the exploitation likelihood of a weakness are evaluated by such authorities as common weakness enumeration (CWE). The consequence properties are confirmed by specialists according to the software requirements. Finally, in the risk calculation, risk degree and overall risk value are calculated by using exponential method and weighted average method respectively. Furthermore, we illustrate the application of our OOPN-SRAM method with realistic examples including web-banking and forum, and make a comparison with traditional methods. The results show that OOPN-SRAM not only increases the efficiency of the evaluation process, but also makes the evaluation result more objective and accurate.
S K Sharma - One of the best experts on this subject based on the ideXlab platform.
-
Interpreting the Objective Outcome of the Proposed Misuse Case Oriented Quality Requirements (MCOQR) Framework Metrics for Security Quantification
Performance Management of Integrated Systems and its Applications in Software Engineering, 2020Co-Authors: Ajeet Singh Poonia, C. Banerjee, Arpita Banerjee, S K SharmaAbstract:A number of tools, techniques, methods, methodology, and standards are available to quantify the security aspect of software during its development and after it has been implemented. But the interpretation and analysis of the quantified security metrics thus obtained may be difficult for the software development team. Proper and comprehensive interpretation and analysis of quantified security metrics are essential to specify correct security requirements during the requirements engineering phase of SDLC which may result in more secured software. This research work shows how the proposed Misuse Case Oriented Quality Requirements (MCOQR) framework metrics may be used to provide identification, definition, interpretation, and analysis of security metrics during the requirements engineering phase of software development process. The authors also discuss the various primary outcomes that may be obtained using the proposed MCOQR framework metrics using the industry accepted standards like common Vulnerability Scoring System (CVSS), common Vulnerability enumeration (CVE), and common weakness enumeration (CWE). The work proposed is an extension of Misuse Case Oriented Quality Requirements (MCOQR) framework metrics and includes software application-specific database. The study also highlights the areas where future research work can be carried out to further strengthen the entire software system during the software development process.
-
Proposed Data Structure for Storage of Metrics Values: Misuse Case Oriented Quality Requirements (MCOQR) Framework Perspective
Asset Analytics, 2019Co-Authors: Sunita Choudhary, Ajeet Singh Poonia, C. Banerjee, Arpita Banerjee, S K SharmaAbstract:Security may be quantified to measure the level of software security implementation. These quantified measures are called security metrics. These metrics need to be stored in some central or local repository for further analysis and refinement of security of software proposed to be developed or modified. Through the research work carried out by the researchers, it is proposed to have a data structure for storage of metrics values which are identified and collected using the Misuse Case Oriented Quality Requirements (MCOQR) framework. The research work highlights and discusses the internal arrangement of various data sets in the data structure and their relationship with each other. The data sets thus proposed are properly synchronized with the industry accepted standards like common Vulnerability Scoring System (CVSS), common Vulnerability enumeration (CVE), and common weakness enumeration (CWE). The work proposed is an extension of Misuse Case Oriented Quality Requirements (MCOQR) framework and metrics and includes software application-specific database. The research work also highlights the areas where further research work can be carried out to further strengthen the entire system.
Suzanna Schmeelk - One of the best experts on this subject based on the ideXlab platform.
-
PASTE - Towards a unified fault-detection benchmark
Proceedings of the 9th ACM SIGPLAN-SIGSOFT workshop on Program analysis for software tools and engineering - PASTE '10, 2010Co-Authors: Suzanna SchmeelkAbstract:Developing a unified benchmark to compare and contrast ways to detect faults is an important aspect for the future of fault detection. In this paper, we explore benchmarks used in the evaluation of popular static analysis tools in order to raise awareness for the community to work towards a unified benchmark. Additionally, we introduce an initial design for a bottom-up repository to integrate benchmarks directly with the web interface of the accessible fault taxonomy, the common weakness enumeration (CWE). The repository would be dynamically linked directly into the evolving CWE. It would reflect new faults, new fault attributes, new test cases and test case attributes. The repository could be dynamically used to aggregate, compare, improve and store information about benchmarks.
-
Managing Post-Development Fault Removal
2009 Sixth International Conference on Information Technology: New Generations, 2009Co-Authors: Suzanna Schmeelk, Bill Mills, Robert NoonanAbstract:In this paper, we manage fault removal by classifying and prioritizing fault warnings reported by a static analysis tool. We present our findings from analyzing three cross-platform industrial code bases at Yahoo! totaling approximately 3.6+ MLOC. The tool found 1.2K potential fault warnings as follows: 52.29% true faults and 47.71% false/noise. The 52.29% correctly reported faults were prioritized based on severity. Additionally, we connected the tool classification to a standard software weakness schema, common weakness enumeration (CWE) to standardized discourse. The results from creating a management system for post-development fault removal are intended to be shifted back into earlier stages of software development.
-
ITNG - Managing Post-Development Fault Removal
2009 Sixth International Conference on Information Technology: New Generations, 2009Co-Authors: Suzanna Schmeelk, Bill Mills, Robert E. NoonanAbstract:In this paper, we manage fault removal by classifying and prioritizing fault warnings reported by a static analysis tool. We present our findings from analyzing three cross-platform industrial code bases at Yahoo! totaling approximately 3.6+ MLOC. The tool found 1.2K potential fault warnings as follows: 52.29% true faults and 47.71% false/noise. The 52.29% correctly reported faults were prioritized based on severity. Additionally, we connected the tool classification to a standard software weakness schema, common weakness enumeration (CWE) to standardized discourse. The results from creating a management system for post-development fault removal are intended to be shifted back into earlier stages of software development.
Xiaohong Li - One of the best experts on this subject based on the ideXlab platform.
-
ICONIP (3) - Embedding and Predicting Software Security Entity Relationships: A Knowledge Graph Based Approach.
Neural Information Processing, 2019Co-Authors: Hongbo Xiao, Zhenchang Xing, Xiaohong LiAbstract:Software security knowledge involves heterogeneous security concepts (e.g., software weaknesses and attack patterns) and security instances (e.g., the vulnerabilities of a particular software product), which can be regarded as software security entities. Among software security entities, there are many within-type relationships as well as many across-type relationships. Predicting software security entity relationships helps to enrich software security knowledge (e.g., finding missing relationships among existing entities). Unfortunately, software security entities are currently documented in separate databases, such as common Vulnerabilities and Exposures (CVE), common weakness enumeration (CWE) and common Attack Pattern enumeration and Classification (CAPEC). This hyper-document representation cannot support effective reasoning of software entity relationships. In this paper, we propose to consolidate heterogeneous software security concepts and instances from separate databases into a coherent knowledge graph. We develop a knowledge graph embedding method which embeds the symbolic relational and descriptive information of software security entities into a continuous vector space. The resulting entity and relationship embeddings are predictive for software security entity relationships. Based on the Open World Assumption, we conduct extensive experiments to evaluate the effectiveness of our knowledge graph based approach for predicting various within-type and across-type relationships of software security entities.
-
DeepWeak: Reasoning common software weaknesses via knowledge graph embedding
2018 IEEE 25th International Conference on Software Analysis Evolution and Reengineering (SANER), 2018Co-Authors: Xiaohong Li, Zhenchang Xing, Zhiyong FengAbstract:common software weaknesses, such as improper input validation, integer overflow, can harm system security directly or indirectly, causing adverse effects such as denial-of-service, execution of unauthorized code. common weakness enumeration (CWE) maintains a standard list and classification of common software weakness. Although CWE contains rich information about software weaknesses, including textual descriptions, common sequences and relations between software weaknesses, the current data representation, i.e., hyperlined documents, does not support advanced reasoning tasks on software weaknesses, such as prediction of missing relations and common consequences of CWEs. Such reasoning tasks become critical to managing and analyzing large numbers of common software weaknesses and their relations. In this paper, we propose to represent common software weaknesses and their relations as a knowledge graph, and develop a translation-based, description-embodied knowledge representation learning method to embed both software weaknesses and their relations in the knowledge graph into a semantic vector space. The vector representations (i.e., embeddings) of software weaknesses and their relations can be exploited for knowledge acquisition and inference. We conduct extensive experiments to evaluate the performance of software weakness and relation embeddings in three reasoning tasks, including CWE link prediction, CWE triple classification, and common consequence prediction. Our knowledge graph embedding approach outperforms other description- and/or structure-based representation learning methods.
-
SANER - DeepWeak: Reasoning common software weaknesses via knowledge graph embedding
2018 IEEE 25th International Conference on Software Analysis Evolution and Reengineering (SANER), 2018Co-Authors: Xiaohong Li, Zhenchang Xing, Zhiyong FengAbstract:common software weaknesses, such as improper input validation, integer overflow, can harm system security directly or indirectly, causing adverse effects such as denial-of-service, execution of unauthorized code. common weakness enumeration (CWE) maintains a standard list and classification of common software weakness. Although CWE contains rich information about software weaknesses, including textual descriptions, common sequences and relations between software weaknesses, the current data representation, i.e., hyperlined documents, does not support advanced reasoning tasks on software weaknesses, such as prediction of missing relations and common consequences of CWEs. Such reasoning tasks become critical to managing and analyzing large numbers of common software weaknesses and their relations. In this paper, we propose to represent common software weaknesses and their relations as a knowledge graph, and develop a translation-based, description-embodied knowledge representation learning method to embed both software weaknesses and their relations in the knowledge graph into a semantic vector space. The vector representations (i.e., embeddings) of software weaknesses and their relations can be exploited for knowledge acquisition and inference. We conduct extensive experiments to evaluate the performance of software weakness and relation embeddings in three reasoning tasks, including CWE link prediction, CWE triple classification, and common consequence prediction. Our knowledge graph embedding approach outperforms other description- and/or structure-based representation learning methods.
-
ICECCS - OOPN-SRAM: A Novel Method for Software Risk Assessment
2014 19th International Conference on Engineering of Complex Computer Systems, 2014Co-Authors: Xiaofei Wu, Xiaohong Li, Ruitao Feng, Guangquan Xu, Jing Hu, Zhiyong FengAbstract:This paper proposes a Software Risk Assessment Method based on Object-Oriented Petri Net (OOPN-SRAM), in which risk assessment procedure is divided into four steps, expressed as four corresponding objects, including asset recognition, weakness analysis, consequence property confirmation and risk calculation. Each object is modeled with Petri net. Specialists recognize software assets by the 1-9 scales method of Analytic Hierarchy Process (AHP). The weaknesses in a system are found by the vulnerability scanner. The damage degree and the exploitation likelihood of a weakness are evaluated by such authorities as common weakness enumeration (CWE). The consequence properties are confirmed by specialists according to the software requirements. Finally, in the risk calculation, risk degree and overall risk value are calculated by using exponential method and weighted average method respectively. Furthermore, we illustrate the application of our OOPN-SRAM method with realistic examples including web-banking and forum, and make a comparison with traditional methods. The results show that OOPN-SRAM not only increases the efficiency of the evaluation process, but also makes the evaluation result more objective and accurate.
-
OOPN-SRAM: A Novel Method for Software Risk Assessment
2014 19th International Conference on Engineering of Complex Computer Systems, 2014Co-Authors: Xiaofei Wu, Xiaohong Li, Ruitao Feng, Guangquan Xu, Jing Hu, Zhiyong FengAbstract:This paper proposes a Software Risk Assessment Method based on Object-Oriented Petri Net (OOPN-SRAM), in which risk assessment procedure is divided into four steps, expressed as four corresponding objects, including asset recognition, weakness analysis, consequence property confirmation and risk calculation. Each object is modeled with Petri net. Specialists recognize software assets by the 1-9 scales method of Analytic Hierarchy Process (AHP). The weaknesses in a system are found by the vulnerability scanner. The damage degree and the exploitation likelihood of a weakness are evaluated by such authorities as common weakness enumeration (CWE). The consequence properties are confirmed by specialists according to the software requirements. Finally, in the risk calculation, risk degree and overall risk value are calculated by using exponential method and weighted average method respectively. Furthermore, we illustrate the application of our OOPN-SRAM method with realistic examples including web-banking and forum, and make a comparison with traditional methods. The results show that OOPN-SRAM not only increases the efficiency of the evaluation process, but also makes the evaluation result more objective and accurate.
Andreas Polze - One of the best experts on this subject based on the ideXlab platform.
-
QRS Companion - An Error Model for Multi-threaded Single-Node Applications, and Its Implementation
2016 IEEE International Conference on Software Quality Reliability and Security Companion (QRS-C), 2016Co-Authors: Lena Feinbube, Daniel Richter, Andreas PolzeAbstract:The fault tolerance of complex software systems can be assessed experimentally using fault injection. To become an effective and systematic testing strategy, fault injection requires a realistic and well-defined failure cause model. However, such failure cause models are frequently incomplete, informal, and implicit or application-dependent. In this paper, we present a formal error model tailored for multi-threaded single-node applications. Based on the community-maintained common weakness enumeration (CWE) database of real world software problems, we derive classes of error states which are either static, i.e., detectable from a snapshot of the system, or dynamic, i.e., dependent on the history of previous states. We then show how to implement our error model so that it becomes executable in our fault injection tool, Hovac.
-
An Error Model for Multi-threaded Single-Node Applications, and Its Implementation
2016 IEEE International Conference on Software Quality Reliability and Security Companion (QRS-C), 2016Co-Authors: Lena Feinbube, Daniel Richter, Andreas PolzeAbstract:The fault tolerance of complex software systems can be assessed experimentally using fault injection. To become an effective and systematic testing strategy, fault injection requires a realistic and well-defined failure cause model. However, such failure cause models are frequently incomplete, informal, and implicit or application-dependent. In this paper, we present a formal error model tailored for multi-threaded single-node applications. Based on the community-maintained common weakness enumeration (CWE) database of real world software problems, we derive classes of error states which are either static, i.e., detectable from a snapshot of the system, or dynamic, i.e., dependent on the history of previous states. We then show how to implement our error model so that it becomes executable in our fault injection tool, Hovac.
-
QRS - Hovac: A Configurable Fault Injection Framework for Benchmarking the Dependability of C/C++ Applications
2015 IEEE International Conference on Software Quality Reliability and Security, 2015Co-Authors: Lena Herscheid, Daniel Richter, Andreas PolzeAbstract:The increasing usage of third-party software and complexity of modern software systems makes dependability, in particular robustness against faulty code, an ever more important concern. To compare and quantitatively assess the dependability of different software systems, dependability benchmarks are needed. We present a configurable tool for dependability benchmarking, Hovac, which uses DLL API hooking to inject faults into third party library calls. Our fault classes are implemented based on the common weakness enumeration (CWE) database, a community maintained source of real life software faults and errors. Using two example applications, we discuss a detailed and systematic approach to benchmarking the dependability of C/C++ applications using our tool.
-
Hovac: A Configurable Fault Injection Framework for Benchmarking the Dependability of C/C++ Applications
2015 IEEE International Conference on Software Quality Reliability and Security, 2015Co-Authors: Lena Herscheid, Daniel Richter, Andreas PolzeAbstract:The increasing usage of third-party software and complexity of modern software systems makes dependability, in particular robustness against faulty code, an ever more important concern. To compare and quantitatively assess the dependability of different software systems, dependability benchmarks are needed. We present a configurable tool for dependability benchmarking, Hovac, which uses DLL API hooking to inject faults into third party library calls. Our fault classes are implemented based on the common weakness enumeration (CWE) database, a community maintained source of real life software faults and errors. Using two example applications, we discuss a detailed and systematic approach to benchmarking the dependability of C/C++ applications using our tool.