Static detection of control-flow-related vulnerabilities using graph embedding

Xiao Cheng, Haoyu Wang*, Jiayi Hua, Miao Zhang, Guoai Xu, Li Yi, Yulei Sui

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

Static vulnerability detection has shown its effectiveness in detecting well-defined low-level memory errors. However, high-level control-flow related (CFR) vulnerabilities, such as insufficient control flow management (CWE-691), business logic errors (CWE-840), and program behavioral problems (CWE-438), which are often caused by a wide variety of bad programming practices, posing a great challenge for existing general static analysis solutions. This paper presents a new deep-learning-based graph embedding approach to accurate detection of CFR vulnerabilities. Our approach makes a new attempt by applying a recent graph convolutional network to embed code fragments in a compact and low-dimensional representation that preserves high-level control-flow information of a vulnerable program. We have conducted our experiments using 8,368 real-world vulnerable programs by comparing our approach with several traditional static vulnerability detectors and state-of-the-art machine-learning-based approaches. The experimental results show the effectiveness of our approach in terms of both accuracy and recall. Our research has shed light on the promising direction of combining program analysis with deep learning techniques to address the general static analysis challenges.

Original languageEnglish
Title of host publication2019 24th International Conference on Engineering of Complex Computer Systems ICECCS 2019
Subtitle of host publicationproceedings
Place of PublicationPiscataway, NJ
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages41-50
Number of pages10
ISBN (Electronic)9781728146461
ISBN (Print)9781728146478
DOIs
Publication statusPublished - Nov 2019
Externally publishedYes
Event24th International Conference on Engineering of Complex Computer Systems, ICECCS 2019 - Guangzhou, China
Duration: 10 Nov 201913 Nov 2019

Conference

Conference24th International Conference on Engineering of Complex Computer Systems, ICECCS 2019
Country/TerritoryChina
CityGuangzhou
Period10/11/1913/11/19

Keywords

  • Control-flow
  • Graph embedding
  • Static analysis
  • Vulnerabilities

Fingerprint

Dive into the research topics of 'Static detection of control-flow-related vulnerabilities using graph embedding'. Together they form a unique fingerprint.

Cite this