The Experts below are selected from a list of 3747 Experts worldwide ranked by ideXlab platform
Hamid Reza Shahriari - One of the best experts on this subject based on the ideXlab platform.
-
Software Vulnerability analysis and discovery using machine learning and data mining techniques a survey
ACM Computing Surveys, 2017Co-Authors: Seyed Mohammad Ghaffarian, Hamid Reza ShahriariAbstract:Software security vulnerabilities are one of the critical issues in the realm of computer security. Due to their potential high severity impacts, many different approaches have been proposed in the past decades to mitigate the damages of Software vulnerabilities. Machine-learning and data-mining techniques are also among the many approaches to address this issue. In this article, we provide an extensive review of the many different works in the field of Software Vulnerability analysis and discovery that utilize machine-learning and data-mining techniques. We review different categories of works in this domain, discuss both advantages and shortcomings, and point out challenges and some uncharted territories in the field.
-
Software Vulnerability Analysis and Discovery Using Machine-Learning and Data-Mining Techniques
ACM Computing Surveys, 2017Co-Authors: Seyed Mohammad Ghaffarian, Hamid Reza ShahriariAbstract:Software security vulnerabilities are one of the critical issues in the realm of computer security. Due to their potential high severity impacts, many different approaches have been proposed in the past decades to mitigate the damages of Software vulnerabilities. Machine-learning and data-mining techniques are also among the many approaches to address this issue. In this article, we provide an extensive review of the many different works in the field of Software Vulnerability analysis and discovery that utilize machine-learning and data-mining techniques. We review different categories of works in this domain, discuss both advantages and shortcomings, and point out challenges and some uncharted territories in the field.
Seyed Mohammad Ghaffarian - One of the best experts on this subject based on the ideXlab platform.
-
Software Vulnerability analysis and discovery using machine learning and data mining techniques a survey
ACM Computing Surveys, 2017Co-Authors: Seyed Mohammad Ghaffarian, Hamid Reza ShahriariAbstract:Software security vulnerabilities are one of the critical issues in the realm of computer security. Due to their potential high severity impacts, many different approaches have been proposed in the past decades to mitigate the damages of Software vulnerabilities. Machine-learning and data-mining techniques are also among the many approaches to address this issue. In this article, we provide an extensive review of the many different works in the field of Software Vulnerability analysis and discovery that utilize machine-learning and data-mining techniques. We review different categories of works in this domain, discuss both advantages and shortcomings, and point out challenges and some uncharted territories in the field.
-
Software Vulnerability Analysis and Discovery Using Machine-Learning and Data-Mining Techniques
ACM Computing Surveys, 2017Co-Authors: Seyed Mohammad Ghaffarian, Hamid Reza ShahriariAbstract:Software security vulnerabilities are one of the critical issues in the realm of computer security. Due to their potential high severity impacts, many different approaches have been proposed in the past decades to mitigate the damages of Software vulnerabilities. Machine-learning and data-mining techniques are also among the many approaches to address this issue. In this article, we provide an extensive review of the many different works in the field of Software Vulnerability analysis and discovery that utilize machine-learning and data-mining techniques. We review different categories of works in this domain, discuss both advantages and shortcomings, and point out challenges and some uncharted territories in the field.
Jinfu Chen - One of the best experts on this subject based on the ideXlab platform.
-
Research on Evaluation Index System for Software Vulnerability Analysis Methods
2019 IEEE Fourth International Conference on Data Science in Cyberspace (DSC), 2019Co-Authors: Jin Li, Min-huan Huang, Shuai-bing Lu, Hu Li, Jinfu ChenAbstract:Due to the diversity of existing Software Vulnerability analysis methods, a unified index system is required if we are to accurately and comprehensively evaluate the analytic effects in order to further improve the level of analysis. Accordingly, this paper first proposes the principles and process necessary to construct an evaluation index system for Software Vulnerability analysis. Moreover, by focusing on the problems identified in previous relevant research, an evaluation index system for Software Vulnerability analysis methods that contains four aspects-accuracy, coverage, value and performance-is proposed; this system is more comprehensive and complete than existing achievements. Finally, using the Vulnerability analysis testing framework, the indexes of the three different versions of cppcheck are measured. The results show that the proposed evaluation index system can be used for the comparative evaluation of different Vulnerability analysis methods.
-
DSC - Research on Evaluation Index System for Software Vulnerability Analysis Methods
2019 IEEE Fourth International Conference on Data Science in Cyberspace (DSC), 2019Co-Authors: Jin Li, Min-huan Huang, Shuai-bing Lu, Hu Li, Jinfu ChenAbstract:Due to the diversity of existing Software Vulnerability analysis methods, a unified index system is required if we are to accurately and comprehensively evaluate the analytic effects in order to further improve the level of analysis. Accordingly, this paper first proposes the principles and process necessary to construct an evaluation index system for Software Vulnerability analysis. Moreover, by focusing on the problems identified in previous relevant research, an evaluation index system for Software Vulnerability analysis methods that contains four aspects-accuracy, coverage, value and performance-is proposed; this system is more comprehensive and complete than existing achievements. Finally, using the Vulnerability analysis testing framework, the indexes of the three different versions of cppcheck are measured. The results show that the proposed evaluation index system can be used for the comparative evaluation of different Vulnerability analysis methods.
-
A Method for Software Vulnerability Detection Based on Improved Control Flow Graph
Wuhan University Journal of Natural Sciences, 2019Co-Authors: Minmin Zhou, Hilary Ackah-arthur, Qingchen Zhang, Shujie Chen, Jinfu Chen, Zhifeng ZengAbstract:With the rapid development of Software technology, Software Vulnerability has become a major threat to computer security. The timely detection and repair of potential vulnerabilities in Software, are of great significance in reducing system crashes and maintaining system security and integrity. This paper focuses on detecting three common types of vulnerabilities: Unused_ Variable, Use_of_Uninitialized_Variable, and Use_After_ Free. We propose a method for Software Vulnerability detection based on an improved control flow graph (ICFG) and several predicates of Vulnerability properties for each type of Vulnerability. We also define a set of grammar rules for analyzing and deriving the three mentioned types of vulnerabilities, and design three Vulnerability detection algorithms to guide the process of Vulnerability detection. In addition, we conduct cases studies of the three mentioned types of vulnerabilities with real Vulnerability program segments from Common Weakness Enumeration (CWE). The results of the studies show that the proposed method can detect the Vulnerability in the tested program segments. Finally, we conduct manual analysis and experiments on detecting the three types of Vulnerability program segments (30 examples for each type) from CWE, to compare the Vulnerability detection effectiveness of the proposed method with that of the existing detection tool CppCheck. The results show that the proposed method performs better. In summary, the method proposed in this paper has certain feasibility and effectiveness in detecting the three mentioned types of vulnerabilities, and it will also have guiding significance for the detection of other common vulnerabilities.
-
A new method to construct the Software Vulnerability model
2017 2nd IEEE International Conference on Computational Intelligence and Applications (ICCIA), 2017Co-Authors: Xiang Li, Jinfu Chen, Lin Zhang, Zibin Wang, Minmin ZhouAbstract:With the development of information technology, Software plays an increasingly important role in the process of social development. However, at the same time, the number of Software vulnerabilities is growing, posing a threat to national security and social stability. Therefore, some scholars and research institutions are paying their attention to the study of Software Vulnerability. In this paper, we propose a new Vulnerability model construction method by considering the Vulnerability causes and characteristics. Firstly, the causes and characteristics of Software Vulnerability are analyzed, and a formal Vulnerability model is also established. Based on the causes and characteristics of Software Vulnerability, we establish the Vulnerability model using the extended chemical abstract machine and deduce the Software Vulnerability through a formal method. We verified the effectiveness and efficiency of the proposed model using Software Vulnerability datasets. In addition, a prototype system is also designed and implemented. Experimental results show that the proposed model is more effective than other methods in the detection of Software vulnerabilities.
-
CBD - A Mining Approach to Obtain the Software Vulnerability Characteristics
2017 Fifth International Conference on Advanced Cloud and Big Data (CBD), 2017Co-Authors: Xiang Li, Jinfu Chen, Lin Zhang, Zibin Wang, Minmin ZhouAbstract:Software Vulnerability remains a serious challenge to the Software engineering domain over the past decade as a result of the recent technological advancement in information systems. The rapid development in Software applications and failure on the part of system developers to properly analyze program codes before been released to the market increases the chance for data breaches. It is a known fact that most system failures are as a result of bugs and errors detected in Software applications. Although code errors significantly affect Software quality, there is no effective method that can be used in eliminating Software errors to improve its reliability. Data Mining and its related algorithms are an active area which can successfully be applied in analyzing Software Vulnerability. However the concept of applying data mining techniques has not been empirically proven as an effective method for obtaining the essential characteristics of Software Vulnerability. To investigate this effect, we propose a Vulnerability mining algorithm to analyze and obtain the essential characteristics of Software Vulnerability based data mining techniques. We first extracted and preprocessed the Software vulnerabilities using data mining techniques and common Vulnerability database. We evaluate the proposed technique using the Common Vulnerability and Exposure (CVE) Database, Common Weakness Enumeration (CWE) Database, National Vulnerability Database (NVD) datasets. Empirical results show that the proposed Vulnerability mining algorithm has a remarkable improvement in the Vulnerability mining process. The most interesting finding is that, we observed that across all the three projects, recall was around 70% and precision was approximately 60%.
Minmin Zhou - One of the best experts on this subject based on the ideXlab platform.
-
A Method for Software Vulnerability Detection Based on Improved Control Flow Graph
Wuhan University Journal of Natural Sciences, 2019Co-Authors: Minmin Zhou, Hilary Ackah-arthur, Qingchen Zhang, Shujie Chen, Jinfu Chen, Zhifeng ZengAbstract:With the rapid development of Software technology, Software Vulnerability has become a major threat to computer security. The timely detection and repair of potential vulnerabilities in Software, are of great significance in reducing system crashes and maintaining system security and integrity. This paper focuses on detecting three common types of vulnerabilities: Unused_ Variable, Use_of_Uninitialized_Variable, and Use_After_ Free. We propose a method for Software Vulnerability detection based on an improved control flow graph (ICFG) and several predicates of Vulnerability properties for each type of Vulnerability. We also define a set of grammar rules for analyzing and deriving the three mentioned types of vulnerabilities, and design three Vulnerability detection algorithms to guide the process of Vulnerability detection. In addition, we conduct cases studies of the three mentioned types of vulnerabilities with real Vulnerability program segments from Common Weakness Enumeration (CWE). The results of the studies show that the proposed method can detect the Vulnerability in the tested program segments. Finally, we conduct manual analysis and experiments on detecting the three types of Vulnerability program segments (30 examples for each type) from CWE, to compare the Vulnerability detection effectiveness of the proposed method with that of the existing detection tool CppCheck. The results show that the proposed method performs better. In summary, the method proposed in this paper has certain feasibility and effectiveness in detecting the three mentioned types of vulnerabilities, and it will also have guiding significance for the detection of other common vulnerabilities.
-
A new method to construct the Software Vulnerability model
2017 2nd IEEE International Conference on Computational Intelligence and Applications (ICCIA), 2017Co-Authors: Xiang Li, Jinfu Chen, Lin Zhang, Zibin Wang, Minmin ZhouAbstract:With the development of information technology, Software plays an increasingly important role in the process of social development. However, at the same time, the number of Software vulnerabilities is growing, posing a threat to national security and social stability. Therefore, some scholars and research institutions are paying their attention to the study of Software Vulnerability. In this paper, we propose a new Vulnerability model construction method by considering the Vulnerability causes and characteristics. Firstly, the causes and characteristics of Software Vulnerability are analyzed, and a formal Vulnerability model is also established. Based on the causes and characteristics of Software Vulnerability, we establish the Vulnerability model using the extended chemical abstract machine and deduce the Software Vulnerability through a formal method. We verified the effectiveness and efficiency of the proposed model using Software Vulnerability datasets. In addition, a prototype system is also designed and implemented. Experimental results show that the proposed model is more effective than other methods in the detection of Software vulnerabilities.
-
CBD - A Mining Approach to Obtain the Software Vulnerability Characteristics
2017 Fifth International Conference on Advanced Cloud and Big Data (CBD), 2017Co-Authors: Xiang Li, Jinfu Chen, Lin Zhang, Zibin Wang, Minmin ZhouAbstract:Software Vulnerability remains a serious challenge to the Software engineering domain over the past decade as a result of the recent technological advancement in information systems. The rapid development in Software applications and failure on the part of system developers to properly analyze program codes before been released to the market increases the chance for data breaches. It is a known fact that most system failures are as a result of bugs and errors detected in Software applications. Although code errors significantly affect Software quality, there is no effective method that can be used in eliminating Software errors to improve its reliability. Data Mining and its related algorithms are an active area which can successfully be applied in analyzing Software Vulnerability. However the concept of applying data mining techniques has not been empirically proven as an effective method for obtaining the essential characteristics of Software Vulnerability. To investigate this effect, we propose a Vulnerability mining algorithm to analyze and obtain the essential characteristics of Software Vulnerability based data mining techniques. We first extracted and preprocessed the Software vulnerabilities using data mining techniques and common Vulnerability database. We evaluate the proposed technique using the Common Vulnerability and Exposure (CVE) Database, Common Weakness Enumeration (CWE) Database, National Vulnerability Database (NVD) datasets. Empirical results show that the proposed Vulnerability mining algorithm has a remarkable improvement in the Vulnerability mining process. The most interesting finding is that, we observed that across all the three projects, recall was around 70% and precision was approximately 60%.
-
TrustCom/BigDataSE/ICESS - An Integration Testing Platform for Software Vulnerability Detection Method
2017 IEEE Trustcom BigDataSE ICESS, 2017Co-Authors: Jin Li, Minmin Zhou, Jinfu Chen, Min-huan Huang, Lin ZhangAbstract:Software Vulnerability detecting is an important way of discovering the existing loopholes in Software in order to ensure the information security. With the rapid development of the information technology in our society, a large variety of application Software with various potentially vulnerabilities has emerged. Therefore, a timely discovery and repair of these loopholes before they are exploited by attackers can effectively reduce the threat in the information system. It is of great significance for us to take the initiative to explore and analyze the system security loopholes, so that the danger or threat to the system will be effectively reduced. From the previous research on the Software Vulnerability detection we have found that each of the existing Vulnerability detection methods or tools can only perform well in some particular occasions. In order to overcome such shortcoming and improve these existing detection methods, we present a more accurate and complete analysis of current mainstream detection methods as well as design a set of evaluation criteria for different detection methods in this paper. Meanwhile, we also propose and design an integrated test framework, on which we can test the typical static analysis methods and dynamic mining methods as well as make the comparison, so that we can obtain an intuitive comparative analysis of the results. Finally, we report the experimental analysis to verify the feasibility and effectiveness of the proposed evaluation method and the testing framework, with the results showing that the final test results will serve as a form of guidance to aid the selection of the most appropriate and effective method or tools in Vulnerability detection activity.
-
A Mining Approach to Obtain the Software Vulnerability Characteristics
2017 Fifth International Conference on Advanced Cloud and Big Data (CBD), 2017Co-Authors: Xiang Li, Jinfu Chen, Lin Zhang, Zibin Wang, Minmin ZhouAbstract:Software Vulnerability remains a serious challenge to the Software engineering domain over the past decade as a result of the recent technological advancement in information systems. The rapid development in Software applications and failure on the part of system developers to properly analyze program codes before been released to the market increases the chance for data breaches. It is a known fact that most system failures are as a result of bugs and errors detected in Software applications. Although code errors significantly affect Software quality, there is no effective method that can be used in eliminating Software errors to improve its reliability. Data Mining and its related algorithms are an active area which can successfully be applied in analyzing Software Vulnerability. However the concept of applying data mining techniques has not been empirically proven as an effective method for obtaining the essential characteristics of Software Vulnerability. To investigate this effect, we propose a Vulnerability mining algorithm to analyze and obtain the essential characteristics of Software Vulnerability based data mining techniques. We first extracted and preprocessed the Software vulnerabilities using data mining techniques and common Vulnerability database. We evaluate the proposed technique using the Common Vulnerability and Exposure (CVE) Database, Common Weakness Enumeration (CWE) Database, National Vulnerability Database (NVD) datasets. Empirical results show that the proposed Vulnerability mining algorithm has a remarkable improvement in the Vulnerability mining process. The most interesting finding is that, we observed that across all the three projects, recall was around 70% and precision was approximately 60%.
Muhammad Zubair Shafiq - One of the best experts on this subject based on the ideXlab platform.
-
A large scale exploratory analysis of Software Vulnerability life cycles
2012 34th International Conference on Software Engineering (ICSE), 2012Co-Authors: Muhammad Shahzad, Muhammad Zubair ShafiqAbstract:Software systems inherently contain vulnerabilities that have been exploited in the past resulting in significant revenue losses. The study of Vulnerability life cycles can help in the development, deployment, and maintenance of Software systems. It can also help in designing future security policies and conducting audits of past incidents. Furthermore, such an analysis can help customers to assess the security risks associated with Software products of different vendors. In this paper, we conduct an exploratory measurement study of a large Software Vulnerability data set containing 46310 vulnerabilities disclosed since 1988 till 2011. We investigate vulnerabilities along following seven dimensions: (1) phases in the life cycle of vulnerabilities, (2) evolution of vulnerabilities over the years, (3) functionality of vulnerabilities, (4) access requirement for exploitation of vulnerabilities, (5) risk level of vulnerabilities, (6) Software vendors, and (7) Software products. Our exploratory analysis uncovers several statistically significant findings that have important implications for Software development and deployment.