Fine-grained Commit-level Vulnerability Type Prediction by CWE Tree Structure
Shengyi Pan, Lingfeng Bao, Xin Xia, David Lo, Shanping Li
Abstract
Identifying security patches via code commits to allow early warnings and timely fixes for Open Source Software (OSS) has received increasing attention. However, the existing detection methods can only identify the presence of a patch (i.e., a binary classification) but fail to pinpoint the vulnerability type. In this work, we take the first step to categorize the security patches into fine-grained vulnerability types. Specifically, we use the Common Weakness Enumeration (CWE) as the label and perform fine-grained classification using categories at the third level of the CWE tree. We first formulate the task as a Hierarchical Multi-label Classification (HMC) problem, i.e., inferring a path (a sequence of CWE nodes) from the root of the CWE tree to the node at the target depth. We then propose an approach named TREEVUL with a hierarchical and chained architecture, which manages to utilize the structure information of the CWE tree as prior knowledge of the classification task. We further propose a tree structure aware and beam search based inference algorithm for retrieving the optimal path with the highest merged probability. We collect a large security patch dataset from NVD, consisting of 6,541 commits from 1,560 GitHub OSS repositories. Experimental results show that TREE-VUL significantly outperforms the best performing baselines, with improvements of 5.9%, 25.0%, and 7.7% in terms of weighted F1-score, macro F1-score, and MCC, respectively. We further conduct a user study and a case study to verify the practical value of TREEVUL in enriching the binary patch detection results and improving the data quality of NVD, respectively.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext be21b858-3e20-4255-88b8-daf5bb7bad74Cited by top-tier papers13
- The Devil is in the Tails: How Long-Tailed Code Distributions Impact Large Language ModelsXin Zhou, Kisub Kim, Bowen Xu, Jiakun Liu et al.ASE 2023 · 10 citations
- Neural SZZ AlgorithmLingxiao Tang, Lingfeng Bao, Xin Xia, Zhongdong HuangASE 2023 · 9 citations
- Identifying Affected Libraries and Their Ecosystems for Open Source Software VulnerabilitiesSusheng Wu, Wenyan Song, Kaifeng Huang, Bihuan Chen et al.ICSE 2024 · 9 citations
- Towards More Practical Automation of Vulnerability AssessmentShengyi Pan, Lingfeng Bao, Jiayuan Zhou, Xing Hu et al.ICSE 2024 · 8 citations
- Applying Contrastive Learning to Code Vulnerability Type ClassificationChen Ji, Su Yang, Hongyu Sun, Yuqing ZhangEMNLP 2024 · 6 citations
Builds on7
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 97 citations
- Finding A Needle in a Haystack: Automated Mining of Silent Vulnerability FixesJiayuan Zhou, Michael Pacheco, Zhiyuan Wan, Xin Xia et al.ASE 2021 · 84 citations
- DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task LearningTriet Huynh Minh Le, David Hin, Roland Croft, Muhammad Ali BabarASE 2021 · 62 citations
- Automated unearthing of dangerous issue reportsShengyi Pan, Jiayuan Zhou, Filipe Roseiro Côgo, Xin Xia et al.FSE 2022 · 22 citations
Related papers
- Locating the Security Patches for Disclosed OSS Vulnerabilities with Vulnerability-Commit Correlation RankingXin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao et al.CCS 2021 · 43 citations
- V1SCAN: Discovering 1-day Vulnerabilities in Reused C/C++ Open-source Software Components Using Code Classification TechniquesSeunghoon Woo, Eunjin Choi, Heejo Lee, Hakjoo OhUSENIX Security 2023
- Where is it? Tracing the Vulnerability-relevant Files from Vulnerability ReportsJiamou Sun, Jieshan Chen, Zhenchang Xing, Qinghua Lu et al.ICSE 2024 · 8 citations
- VulChecker: Graph-based Vulnerability Localization in Source CodeYisroel Mirsky, George Macon, Michael D. Brown, Carter Yagemann et al.USENIX Security 2023
- PatchFinder: A Two-Phase Approach to Security Patch Tracing for Disclosed Vulnerabilities in Open-Source SoftwareKaixuan Li, Jian Zhang, Sen Chen, Han Liu et al.ISSTA 2024 · 8 citations
