Improving Vulnerability Inspection Efficiency Using Active Learning

被引:32
作者
Yu, Zhe [1 ]
Theisen, Christopher [2 ]
Williams, Laurie [1 ]
Menzies, Tim [1 ]
机构
[1] North Carolina State Univ, Dept Comp Sci, Raleigh, NC 27695 USA
[2] Microsoft, Seattle, WA 98105 USA
基金
美国国家科学基金会;
关键词
Inspection; Software; Tools; Security; Predictive models; Error correction; NIST; Active learning; security; vulnerabilities; software engineering; error correction;
D O I
10.1109/TSE.2019.2949275
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software engineers can find vulnerabilities with less effort if they are directed towards code that might contain more vulnerabilities. HARMLESS is an incremental support vector machine tool that builds a vulnerability prediction model from the source code inspected to date, then suggests what source code files should be inspected next. In this way, HARMLESS can reduce the time and effort required to achieve some desired level of recall for finding vulnerabilities. The tool also provides feedback on when to stop (at that desired level of recall) while at the same time, correcting human errors by double-checking suspicious files. This paper evaluates HARMLESS on Mozilla Firefox vulnerability data. HARMLESS found 80, 90, 95, 99 percent of the vulnerabilities by inspecting 10, 16, 20, 34 percent of the source code files. When targeting 90, 95, 99 percent recall, HARMLESS could stop after inspecting 23, 30, 47 percent of the source code files. Even when human reviewers fail to identify half of the vulnerabilities (50 percent false negative rate), HARMLESS could detect 96 percent of the missing vulnerabilities by double-checking half of the inspected files. Our results serve to highlight the very steep cost of protecting software from vulnerabilities (in our case study that cost is, for example, the human effort of inspecting 28,750 x 20% = 5,750 source code files to identify 95 percent of the vulnerabilities). While this result could benefit the mission-critical projects where human resources are available for inspecting thousands of source code files, the research challenge for future work is how to further reduce that cost. The conclusion of this paper discusses various ways that goal might be achieved.
引用
收藏
页码:2401 / 2420
页数:20
相关论文
共 50 条
[1]  
[Anonymous], 2011, Proceedings of the SIAM International Conference on Data Mining, SDM '11
[2]  
[Anonymous], 2017, Mozilla Foundation Security Advisories
[3]  
Black P. E., 2016, NAT I STANDARDS TECH
[4]  
Breiman L., 2001, Mach. Learn., V45, P5
[5]  
Chapelle O., 2009, IEEE Trans. Neural Netw., V20, P542, DOI DOI 10.1109/TNN.2009.2015974
[6]   Using complexity, coupling, and cohesion metrics as early indicators of vulnerabilities [J].
Chowdhury, Istehad ;
Zulkernine, Mohammad .
JOURNAL OF SYSTEMS ARCHITECTURE, 2011, 57 (03) :294-313
[7]   The Quest for Total Recall [J].
Cormack, Gordon V. ;
Grossman, Maura R. .
PROCEEDINGS OF THE ACM SYMPOSIUM ON DOCUMENT ENGINEERING (DOCENG 2018), 2018,
[8]   Navigating Imprecision in Relevance Assessments on the Road to Total Recall: Roger and Me [J].
Cormack, Gordon V. ;
Grossman, Maura R. .
SIGIR'17: PROCEEDINGS OF THE 40TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, 2017, :5-14
[9]   Evaluation of Machine-Learning Protocols for Technology-Assisted Review in Electronic Discovery [J].
Cormack, Gordon V. ;
Grossman, Maura R. .
SIGIR'14: PROCEEDINGS OF THE 37TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, 2014, :153-162
[10]   Engineering Quality and Reliability in Technology-Assisted Review [J].
Cormack, Gordon V. ;
Grossman, Maura R. .
SIGIR'16: PROCEEDINGS OF THE 39TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, 2016, :75-84