Software Vulnerability Detection Based on Correlation of Structural Features between Functions
Author:
Affiliation:

Clc Number:

TP311

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Vulnerability detection is a critical technology in software system security. In recent years, deep learning has made significant advances in vulnerability detection due to its exceptionals capability in code feature extraction. However, current deep learning-based approaches focus solely on the independent structural features of code instances, neglecting the structural feature similarities and associations among different vulnerable codes, which limits the performance of vulnerability detection technology. To address this issue, this paper proposes a vulnerability detection method based on the correlation of structural features between functions (CSFF-VD). This method first parses functions into code property graphs and extracts independent structural features within functions using gated graph neural networks. On this basis, it constructs an association network among functions using feature similarity and employs a graph attention network to further extract structural similarity information between functions, thereby enhancing vulnerability detection performance. Experimental results show that CSFF-VD outperforms current deep learning-based vulnerability detection methods on three public vulnerability detection datasets. In addition, based on the extraction of independent features within the function, this paper proves the effectiveness of integrating the correlation information between functions by adding experiments on the inter-function correlation feature extraction method in CSFF-VD.

    Reference
    Related
    Cited by
Get Citation

邱少健,程嘉濠,黄梦阳,黄琼.基于函数间结构特征关联的软件漏洞检测方法.软件学报,2025,36(7):0

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:August 26,2024
  • Revised:October 15,2024
  • Adopted:
  • Online: December 10,2024
  • Published:
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-4
Address:4# South Fourth Street, Zhong Guan Cun, Beijing 100190,Postal Code:100190
Phone:010-62562563 Fax:010-62562533 Email:jos@iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063