• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Towards Automatically Generating Security Analyses from Machine-Learned Library Models
 
  • Details
  • Full
Options
2021
Poster
Title

Towards Automatically Generating Security Analyses from Machine-Learned Library Models

Title Supplement
Paper presented at ESORICS 2021, 26th European Symposium on Research in Computer Security, held virtually, October 4 - 8, 2021
Abstract
Automatic code vulnerability scanners identify security antipatterns in application code, such as insecure uses of library methods. However, current scanners must regularly be updated manually with new library models, patterns, and corresponding security analyses. We propose a novel, two-phase approach called Mod4Sec for automatically generating static and dynamic code analyses targeting vulnerabilities based on library (mis)usage. In the first phase, we automatically infer semantic properties of libraries on a method and parameter level with supervised machine learning. In the second phase, we combine these models with high-level security policies. We present preliminary results from the first phase of Mod4Sec, where we identify security-relevant methods, with categorical f1-scores between 0.81 and 0.93.
Author(s)
Kober, Maria  
Arzt, Steven  
Conference
European Symposium on Research in Computer Security (ESORICS) 2021  
File(s)
Download (276.88 KB)
Rights
Use according to copyright law
DOI
10.24406/publica-fhg-412751
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024