Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories
Peking University · Huawei Technologies (China) · +1 more institution
Abstract
Functionality-specific vulnerabilities, which mainly occur in Application Programming Interfaces (APIs) with specific functionalities, are crucial for software developers to detect and avoid. When detecting individual functionality-specific vulnerabilities, the existing two categories of approaches are ineffective because they consider only the API bodies and are unable to handle diverse implementations of functionality-equivalent APIs. To effectively detect functionality-specific vulnerabilities, we propose APISS, the first approach to utilize API doc strings and signatures instead of API bodies. APISS first retrieves functionality-equivalent APIs for APIs with existing vulnerabilities and then migrates…
Citation impact
- FWCI
- 3142.38
- Percentile
- 100%
- References
- 0
Authors
10- CTChen, TianyuCorresponding
Peking University
- WZWang, Zeyu
Huawei Technologies (China), Huawei Technologies (United States)
- LLLi, Lin
Huawei Technologies (China), Huawei Technologies (United States)
- LDLi, Ding
Peking University
- LZLi, Zongyang
Peking University
Topics & keywords
- Computer science
- Graph
- Convolutional neural network
- Scalability
- Artificial intelligence
- ENCODE
- Margin (machine learning)
- Theoretical computer science