A CNN-based automatic vulnerability detection

被引:4
|
作者
An, Jung Hyun [1 ]
Wang, Zhan [1 ]
Joe, Inwhee [1 ]
机构
[1] Hanyang Univ, Dept Comp Engn, Seoul, South Korea
关键词
Convolutional neural networks; Vulnerabilities; Security; Deep learning; CVE (common vulnerabilities and exposures); CWE (common weakness enumeration);
D O I
10.1186/s13638-023-02255-2
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
With the advent of the Internet, the activities of individuals and businesses have expanded into the online realm. As a result, vulnerabilities that result in actual breaches can lead to data loss and program failure. The number of breaches is increasing every year, as is the number of vulnerabilities. To address this problem, current research focuses on the detection of vulnerabilities using static analysis techniques. To prevent the propagation of vulnerabilities, a new paradigm is needed to quickly detect vulnerabilities, analyze them, and take actions such as blocking or removing them. Recently, artificial intelligence algorithms such as deep learning have been introduced for vulnerability detection. In this paper, we propose a vulnerability detection model, V-CNN, which aims to detect CWE/CVE (Common Weakness Enumeration/Common Vulnerabilities and Exposures) using CNN (convolutional neural network). We trained CWE for deep learning and redefined vulnerabilities based on CWE. We propose an experimental algorithm to improve vulnerability detection. The accuracy of the proposed V-CNN model is 98%, which exceeds the 95% of the random forest model. Therefore, our V-CNN has excellent correctness detection performance in the field of vulnerability detection. The V-CNN vulnerability detection algorithm can be used instead of static analysis to detect various security vulnerabilities.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] A CNN-based automatic vulnerability detection
    Jung Hyun An
    Zhan Wang
    Inwhee Joe
    EURASIP Journal on Wireless Communications and Networking, 2023
  • [2] Application of CNN-Based Method for Automatic Detection and Classification of the IC Packages
    Malinski, Kamil Marek
    Okarma, Krzysztof
    16TH IEEE INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION, ROBOTICS AND VISION (ICARCV 2020), 2020, : 944 - 950
  • [3] CNN-Based Automatic Prioritization of Bug Reports
    Umer, Qasim
    Liu, Hui
    Illahi, Inam
    IEEE TRANSACTIONS ON RELIABILITY, 2020, 69 (04) : 1341 - 1354
  • [4] CNN-Based Automatic Helmet Violation Detection of Motorcyclists for an Intelligent Transportation System
    Waris, Tasbeeha
    Asif, Muhammad
    Ahmad, Maaz Bin
    Mahmood, Toqeer
    Zafar, Sadia
    Shah, Mohsin
    Ayaz, Ahsan
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2022, 2022
  • [5] Software vulnerability detection under poisoning attacks using CNN-based image processing
    Gonzalez-Manzano, Lorena
    Garcia-Alfaro, Joaquin
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2025, 24 (02)
  • [6] CNN-based Android Malware Detection
    Ganesh, Meenu
    Pednekar, Priyanka
    Prabhuswamy, Pooja
    Nair, Divyashri Sreedharan
    Park, Younghee
    Jeon, Hyeran
    PROCEEDINGS 2017 INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND ASSURANCE (ICSSA), 2017, : 60 - 65
  • [7] CNN-based defect detection in manufacturing
    Hou M.
    Li P.
    Cheng S.
    Yv J.
    Advanced Control for Applications: Engineering and Industrial Systems, 2024, 6 (04):
  • [8] Automatic Stones Classification through a CNN-Based Approach
    Tropea, Mauro
    Fedele, Giuseppe
    De Luca, Raffaella
    Miriello, Domenico
    De Rango, Floriano
    SENSORS, 2022, 22 (16)
  • [9] CNN-Based Automatic Modulation Classification in OFDM Systems
    Song, Geonho
    Jang, Mingyu
    Yoon, Dongweon
    2022 INTERNATIONAL CONFERENCE ON COMPUTER, INFORMATION AND TELECOMMUNICATION SYSTEMS, CITS, 2022, : 101 - 104
  • [10] Fusion Methods for CNN-Based Automatic Modulation Classification
    Zheng, Shilian
    Qi, Peihan
    Chen, Shichuan
    Yang, Xiaoniu
    IEEE ACCESS, 2019, 7 : 66496 - 66504