用Transformer分析GitHub问题,自动识别代码漏洞。
Automating the Detection of Code Vulnerabilities by Analyzing GitHub Issues
- 基于Transformer和机器学习分析GitHub问题
- 新数据集支持漏洞相关问题分类,准确率高
- 适合开源项目安全团队提前发现漏洞
在当今数字环境中,及时准确地检测软件漏洞至关重要。本文提出一种新方法,利用基于Transformer的模型和机器学习技术,通过分析GitHub问题自动识别软件漏洞。我们构建了一个专用于漏洞检测问题分类的新数据集,并评估了多种分类技术的有效性。结果表明,该方法在真实场景中具有早期漏洞检测潜力,可显著缩短漏洞暴露时间。本研究的关键贡献在于提供了一个可扩展、计算高效的自动化检测框架,可在官方通知前预防受损软件的使用,有助于提升开源软件生态的安全性。
原文摘要 · Abstract (English)
In today's digital landscape, the importance of timely and accurate vulnerability detection has significantly increased. This paper presents a novel approach that leverages transformer-based models and machine learning techniques to automate the identification of software vulnerabilities by analyzing GitHub issues. We introduce a new dataset specifically designed for classifying GitHub issues relevant to vulnerability detection. We then examine various classification techniques to determine their effectiveness. The results demonstrate the potential of this approach for real-world application in early vulnerability detection, which could substantially reduce the window of exploitation for software vulnerabilities. This research makes a key contribution to the field by providing a scalable and computationally efficient framework for automated detection, enabling the prevention of compromised software usage before official notifications. This work has the potential to enhance the security of open-source software ecosystems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。