Automated Vulnerability Detection Using Deep Learning Technique

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Yang, Guan-Yan, Ko, Yi-Heng, Wang, Farn, Yeh, Kuo-Hui, Chang, Haw-Shiang, Chen, Hsueh-Yi
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866915467006836736
author Yang, Guan-Yan
Ko, Yi-Heng
Wang, Farn
Yeh, Kuo-Hui
Chang, Haw-Shiang
Chen, Hsueh-Yi
author_facet Yang, Guan-Yan
Ko, Yi-Heng
Wang, Farn
Yeh, Kuo-Hui
Chang, Haw-Shiang
Chen, Hsueh-Yi
contents Our work explores the utilization of deep learning, specifically leveraging the CodeBERT model, to enhance code security testing for Python applications by detecting SQL injection vulnerabilities. Unlike traditional security testing methods that may be slow and error-prone, our approach transforms source code into vector representations and trains a Long Short-Term Memory (LSTM) model to identify vulnerable patterns. When compared with existing static application security testing (SAST) tools, our model displays superior performance, achieving higher precision, recall, and F1-score. The study demonstrates that deep learning techniques, particularly with CodeBERT's advanced contextual understanding, can significantly improve vulnerability detection, presenting a scalable methodology applicable to various programming languages and vulnerability types.
format Preprint
id arxiv_https___arxiv_org_abs_2410_21968
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Automated Vulnerability Detection Using Deep Learning Technique
Yang, Guan-Yan
Ko, Yi-Heng
Wang, Farn
Yeh, Kuo-Hui
Chang, Haw-Shiang
Chen, Hsueh-Yi
Cryptography and Security
Artificial Intelligence
Software Engineering
D.2.4; D.2.5
Our work explores the utilization of deep learning, specifically leveraging the CodeBERT model, to enhance code security testing for Python applications by detecting SQL injection vulnerabilities. Unlike traditional security testing methods that may be slow and error-prone, our approach transforms source code into vector representations and trains a Long Short-Term Memory (LSTM) model to identify vulnerable patterns. When compared with existing static application security testing (SAST) tools, our model displays superior performance, achieving higher precision, recall, and F1-score. The study demonstrates that deep learning techniques, particularly with CodeBERT's advanced contextual understanding, can significantly improve vulnerability detection, presenting a scalable methodology applicable to various programming languages and vulnerability types.
title Automated Vulnerability Detection Using Deep Learning Technique
topic Cryptography and Security
Artificial Intelligence
Software Engineering
D.2.4; D.2.5
url https://arxiv.org/abs/2410.21968