用实证方法分析AI在软件安全中的作用,发现上下文信息对漏洞预测至关重要。
Bringing Order Amidst Chaos: On the Role of Artificial Intelligence in Secure Software Engineering
- 通过分析静态检测工具和代码级别特征,识别影响AI预测准确性的关键因素。
- 发现静态分析工具对漏洞类型覆盖不全,严重性评分关联性弱,缺陷预测精度可提升。
- 适合关注软件安全与AI结合的研究者及工程实践人员参考。
开发安全可靠的软件仍是软件工程的核心挑战。技术演进带来机遇与威胁并存,使安全软件工程(SSE)面临持续的漏洞风险,可能危及关键基础设施并造成重大经济损失。研究者探索了静态应用安全测试工具(SASTTs)以及机器学习(ML)和大语言模型(LLMs)等人工智能方法来检测和缓解漏洞。本文采用实证策略,包括评估努力感知指标、分析SASTTs、进行方法级分析,并利用系统数据集审查等证据基础方法,刻画漏洞预测数据集特性。主要发现包括:静态分析工具在识别漏洞方面存在局限;SASTTs对漏洞类型的覆盖率不足;漏洞严重性评分间相关性弱;使用即时建模可提升缺陷预测准确率;未被处理的方法仍构成威胁。研究强调了上下文知识在改进基于AI的漏洞与缺陷预测中的重要性,推动了更有效的预测模型发展,为研究人员和实践者提供支持。
原文摘要 · Abstract (English)
Context. Developing secure and reliable software remains a key challenge in software engineering (SE). The ever-evolving technological landscape offers both opportunities and threats, creating a dynamic space where chaos and order compete. Secure software engineering (SSE) must continuously address vulnerabilities that endanger software systems and carry broader socio-economic risks, such as compromising critical national infrastructure and causing significant financial losses. Researchers and practitioners have explored methodologies like Static Application Security Testing Tools (SASTTs) and artificial intelligence (AI) approaches, including machine learning (ML) and large language models (LLMs), to detect and mitigate these vulnerabilities. Each method has unique strengths and limitations. Aim. This thesis seeks to bring order to the chaos in SSE by addressing domain-specific differences that impact AI accuracy. Methodology. The research employs a mix of empirical strategies, such as evaluating effort-aware metrics, analyzing SASTTs, conducting method-level analysis, and leveraging evidence-based techniques like systematic dataset reviews. These approaches help characterize vulnerability prediction datasets. Results. Key findings include limitations in static analysis tools for identifying vulnerabilities, gaps in SASTT coverage of vulnerability types, weak relationships among vulnerability severity scores, improved defect prediction accuracy using just-in-time modeling, and threats posed by untouched methods. Conclusions. This thesis highlights the complexity of SSE and the importance of contextual knowledge in improving AI-driven vulnerability and defect prediction. The comprehensive analysis advances effective prediction models, benefiting both researchers and practitioners.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。