Proceedings Article10.1109/ICDS50568.2020.9268686
Dynamic vulnerability detection approaches and tools: State of the Art
Oualid Zaazaa,Hanan El Bakkali +1 more
- 21 Oct 2020
11
TL;DR: Some of the most recent dynamic approaches to find vulnerabilities and the efficient of the tools that use them are discussed.
read more
Abstract: Vulnerabilities are everywhere around us. Every device we use in our daily life include a software that may contain vulnerabilities. The growth use of software and devices to automate some of our daily life actions is making these programs more complex and more connected to the internet, which increase the risk of cyber-attacks. To reduce this risk, multiple programming companies are trying to use different approaches to find these vulnerabilities. Some are using static approaches during the software development life cycle while others are using dynamic analysis approaches to find vulnerabilities once the application is correctly working. Unfortunately, both approaches still suffer from multiple limitation and still need improvement. In this paper, we are discussing some of the most recent dynamic approaches and the efficient of the tools that use them.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Continuous and Secure Integration Framework for Smart Contracts
TL;DR: In this article , the authors introduce a framework to implement DevOps for smart contracts development by describing multiple DevOps tools and their applicability to smart contract development, and apply this practice to a smart contract build.
Binary Code Vulnerability Detection Based on Multi-level Feature Fusion
01 Jan 2023
TL;DR: Zhang et al. as mentioned in this paper proposed a binary code vulnerability detection model based on multi-level feature fusion, which considers both word-level and instruction-level features and achieved an F1 score of 98.9 percent on the Juliet Test Suite dataset and a F1-score of 87.7 percent on NDSS18 (Whole) dataset.
Detection of Vulnerabilities by Incorrect Use of Variable Using Machine Learning
Jihyun Park,Byoung Ju Choi +1 more
TL;DR: In this article , the authors proposed a technique to detect the vulnerabilities from incorrect use of a variable in C language using machine learning techniques, which can reduce false alarms and detect vulnerabilities by performing static analysis and dynamic verification.
A Software Vulnerability Detection Method Based on Complex Network Community
TL;DR: The spring-shiro-training project is used to verify the vulnerability detection method based on complex network community, and the results show that the method is effective.
1
Software Vulnerability Detection Based on Anomaly-Attention
Shan Shan Li,Deng Chen,Jun Zhang,Haoyu Wang,Lei Li,Yuyang Qian,Hailun Liu +6 more
- 25 Sep 2022
TL;DR: Wang et al. as discussed by the authors proposed a Transformer software vulnerability detection method based on anomaly-attention, which introduces the Anomaly-Attention mechanism in the traditional Transformer model to calculate the association differences between function call nodes to neighboring points and function call node to the whole sequence respectively.
References
google,我,萨娜
方华
- 01 Jan 2006
TL;DR: After you change your VT Google password, you will be unable to log on to VT Google Apps services including Mail, Drive, Groups, etc.
3.8K
KLEE: unassisted and automatic generation of high-coverage tests for complex systems programs
Cristian Cadar,Daniel Dunbar,Dawson Engler +2 more
- 08 Dec 2008
TL;DR: A new symbolic execution tool, KLEE, capable of automatically generating tests that achieve high coverage on a diverse set of complex and environmentally-intensive programs, and significantly beat the coverage of the developers' own hand-written test suite is presented.
DART: directed automated random testing
Koushik Sen
- 19 Oct 2009
TL;DR: Direct automated random testing is described, an efficient approach which combines random and symbolic testing, and several heuristic search strategies are presented, including a novel strategy guided by the control flow graph of the program under test.
An empirical study of the reliability of UNIX utilities
TL;DR: The following section describes the tools built to test the utilities, including the fuzz (random character) generator, ptyjig (to test interactive utilities), and scripts to automate the testing process.
SOK: (State of) The Art of War: Offensive Techniques in Binary Analysis
Yan Shoshitaishvili,Ruoyu Wang,Christopher Salls,Nick Stephens,Mario Polino,Andrew Dutcher,John Grosen,Siji Feng,Christophe Hauser,Christopher Kruegel,Giovanni Vigna +10 more
- 22 May 2016
TL;DR: This paper presents a binary analysis framework that implements a number of analysis techniques that have been proposed in the past and implements these techniques in a unifying framework, which allows other researchers to compose them and develop new approaches.