Can Neural Decompilation Assist Vulnerability Prediction on Binary Code?

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cotroneo, D., Grasso, F. C., Natella, R., Orbinato, V.
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917970770395136
author Cotroneo, D.
Grasso, F. C.
Natella, R.
Orbinato, V.
author_facet Cotroneo, D.
Grasso, F. C.
Natella, R.
Orbinato, V.
contents Vulnerability prediction is valuable in identifying security issues efficiently, even though it requires the source code of the target software system, which is a restrictive hypothesis. This paper presents an experimental study to predict vulnerabilities in binary code without source code or complex representations of the binary, leveraging the pivotal idea of decompiling the binary file through neural decompilation and predicting vulnerabilities through deep learning on the decompiled source code. The results outperform the state-of-the-art in both neural decompilation and vulnerability prediction, showing that it is possible to identify vulnerable programs with this approach concerning bi-class (vulnerable/non-vulnerable) and multi-class (type of vulnerability) analysis.
format Preprint
id arxiv_https___arxiv_org_abs_2412_07538
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Can Neural Decompilation Assist Vulnerability Prediction on Binary Code?
Cotroneo, D.
Grasso, F. C.
Natella, R.
Orbinato, V.
Cryptography and Security
Artificial Intelligence
Machine Learning
Vulnerability prediction is valuable in identifying security issues efficiently, even though it requires the source code of the target software system, which is a restrictive hypothesis. This paper presents an experimental study to predict vulnerabilities in binary code without source code or complex representations of the binary, leveraging the pivotal idea of decompiling the binary file through neural decompilation and predicting vulnerabilities through deep learning on the decompiled source code. The results outperform the state-of-the-art in both neural decompilation and vulnerability prediction, showing that it is possible to identify vulnerable programs with this approach concerning bi-class (vulnerable/non-vulnerable) and multi-class (type of vulnerability) analysis.
title Can Neural Decompilation Assist Vulnerability Prediction on Binary Code?
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2412.07538