Abstract
Existing static vulnerability detection methods have high false positive and false negative rates. In this paper, we proposed DVCMA, a new method for detecting software vulnerabilities basing on clustering and model analyzing. In this method, clustering technology is introduced to mine patterns from the set of vulnerability sequences. Based on these patterns, vulnerability-pattern-library(VPL) is constructed to improve the efficiency of detecting. Simultaneously, a novel similarity function based on edit distance is designed to reduce false positives and prevent false negatives, and because of the computational complexity of edit distance is high, we also present identification distance to filtrate initially before calculating the similarity. According to VPL, the vulnerabilities hiding in the software will be mined under the similarity measure mechanism, and a new model is established to optimize the process of mining. Experimental results show that our method has lower false positive and false negative rates.
| Original language | English |
|---|---|
| Pages (from-to) | 1065-1073 |
| Number of pages | 9 |
| Journal | Journal of Computational Information Systems |
| Volume | 7 |
| Issue number | 4 |
| Publication status | Published - Apr 2011 |
| Externally published | Yes |
Keywords
- Clustering
- Model analyzing
- Sequence identification
- Vulnerability detection
Fingerprint
Dive into the research topics of 'A method for detecting software vulnerabilities based on clustering and model analyzing'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver