Fetching the paper…
Reading the bibliography…
The detection of software vulnerabilities (or vulnerabilities for short) is an important problem that has yet to be tackled, as manifested by the many vulnerabilities reported on a daily basis.
B. Matthews, “Comparison of the predicted and observed secondary structure of t4 phage lysozyme,” Biochimica et Biophysica Acta (BBA) - Protein Structure , vol. 405, no. 2, pp. 442–451, 1975
1975
Earlier work this paper cites.
R. E. Noonan, “An algorithm for generating abstract syntax trees,” Comput. Lang. , vol. 10, no. 3/4, pp. 225–236, 1985
1985
Earlier work this paper cites.
J. Ferrante, K. J. Ottenstein, and J. D. Warren, “The program dependence graph and its use in optimization,” ACM Trans. Program. Lang. Syst. , vol. 9, no. 3, pp. 319–349, 1987
1987
Earlier work this paper cites.
F. Tip, “A survey of program slicing techniques,” J. Prog. Lang. , vol. 3, no. 3, 1995
1995
Earlier work this paper cites.
S. Lawrence, C. L. Giles, A. C. Tsoi, and A. D. Back, “Face recognition: A convolutional neural-network approach,” IEEE Trans. Neural Networks , vol. 8, no. 1, pp. 98–113, 1997
1997
Earlier work this paper cites.
S. Hochreiter and J. Schmidhuber, “Long short-term memory,” Neural Computation , vol. 9, no. 8, pp. 1735–1780, 1997
1997
Earlier work this paper cites.
A. Graves and J. Schmidhuber, “Framewise phoneme classification with bidirectional LSTM and other neural network architectures,” Neural Networks , vol. 18, no. 5-6, pp. 602–610, 2005
2005
Earlier work this paper cites.
S. Neuhaus, T. Zimmermann, C. Holler, and A. Zeller, “Predicting vulnerable software components,” in Proceedings of 2007 ACM Conference on Computer and Communications Security, Alexandria, Virginia, USA , 2007, pp. 529–540
2007
Earlier work this paper cites.
R. Chang, A. Podgurski, and J. Yang, “Discovering neglected conditions in software by mining dependence graphs,” IEEE Trans. Software Eng. , vol. 34, no. 5, pp. 579–596, 2008
2008
Earlier work this paper cites.
G. E. Hinton, “Deep belief networks,” Scholarpedia , vol. 4, no. 5, p. 5947, 2009
2009
Earlier work this paper cites.
Y. Zhang, R. Jin, and Z. Zhou, “Understanding bag-of-words model: a statistical framework,” Int. J. Machine Learning & Cybernetics , vol. 1, no. 1-4, pp. 43–52, 2010
2010
Earlier work this paper cites.
N. Gruska, A. Wasylkowski, and A. Zeller, “Learning from 6,000 projects: Lightweight cross-project anomaly detection,” in Proceedings of the 19th International Symposium on Software Testing and Analysis, Trento, Italy , 2010, pp. 119–130
2010
Earlier work this paper cites.
Y. Shin, A. Meneely, L. Williams, and J. A. Osborne, “Evaluating complexity, code churn, and developer activity metrics as indicators of software vulnerabilities,” IEEE Trans. Software Eng. , vol. 37, no. 6, pp. 772–787, 2011
2011
Earlier work this paper cites.
F. Yamaguchi, M. Lottmann, and K. Rieck, “Generalized vulnerability extrapolation using abstract syntax trees,” in Proceedings of the 28th Annual Computer Security Applications Conference, Orlando, FL, USA , 2012, pp. 359–368
2012
Earlier work this paper cites.
F. Yamaguchi, C. Wressnegger, H. Gascon, and K. Rieck, “Chucky: Exposing missing checks in source code for vulnerability discovery,” in Proceedings of 2013 ACM SIGSAC Conference on Computer and Communications Security, Berlin, Germany , 2013, pp. 499–510
2013
Earlier work this paper cites.
A. Meneely, H. Srinivasan, A. Musa, A. R. Tejeda, M. Mokary, and B. Spates, “When a patch goes bad: Exploring the properties of vulnerability-contributing commits,” in Proceedings of 2013 ACM / IEEE International Symposium on Empirical Software Engineering and Measurement, Baltimore, Maryland, USA , 2013, pp. 65–74
2013
Earlier work this paper cites.
“Rough Audit Tool for Security,” 2014, https://code.google.com/archive/p/rough-auditing-tool-for-security/
2014
Earlier work this paper cites.
F. Yamaguchi, N. Golde, D. Arp, and K. Rieck, “Modeling and discovering vulnerabilities with code property graphs,” in Proceedings of 2014 IEEE Symposium on Security and Privacy, Berkeley, CA, USA , 2014, pp. 590–604
2014
Earlier work this paper cites.
K. Cho, B. van Merrienboer, D. Bahdanau, and Y. Bengio, “On the properties of neural machine translation: Encoder-decoder approaches,” in Proceedings of the 8th Workshop on Syntax, Semantics and Structure in Statistical Translation, Doha, Qatar , 2014, pp. 103–111
2014
Cited alongside, same era.
J. Walden, J. Stuckman, and R. Scandariato, “Predicting vulnerable components: Software metrics vs text mining,” in Proceedings of the 25th IEEE International Symposium on Software Reliability Engineering, Naples, Italy , 2014, pp. 23–33
2014
Cited alongside, same era.
E. C. R. Shin, D. Song, and R. Moazzezi, “Recognizing functions in binaries with neural networks,” in Proceedings of the 24th USENIX Security Symposium, Washington, D.C., USA , 2015, pp. 611–626
2015
Cited alongside, same era.
X. Yang, D. Lo, X. Xia, Y. Zhang, and J. Sun, “Deep learning for just-in-time defect prediction,” in Proceedings of 2015 IEEE International Conference on Software Quality, Reliability and Security, Vancouver, BC, Canada , 2015, pp. 17–26
J. Li, P. He, J. Zhu, and M. R. Lyu, “Software defect prediction via convolutional neural network,” in Proceedings of 2017 IEEE International Conference on Software Quality, Reliability and Security, Prague, Czech Republic , 2017, pp. 318–328
2017
Later among the works it cites.
J. Wang, J. Sun, H. Lin, H. Dong, and S. Zhang, “Convolutional neural networks for expert recommendation in community question answering,” Sci. China-Inf. Sci. , vol. 60, no. 11, pp. 110 102:1–110 102:9, 2017
2017
Later among the works it cites.
S. Ren, K. He, R. B. Girshick, and J. Sun, “Faster R-CNN: Towards real-time object detection with region proposal networks,” IEEE Trans. Pattern Anal. Mach. Intell. , vol. 39, no. 6, pp. 1137–1149, 2017
2017
Later among the works it cites.
M. Pendleton, R. Garcia-Lebron, J. Cho, and S. Xu, “A survey on systems security metrics,” ACM Comput. Surv. , vol. 49, no. 4, pp. 62:1–62:35, 2017
2017
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2015
Cited alongside, same era.
F. Yamaguchi, “Pattern-based vulnerability discovery,” Ph.D. dissertation, University of Göttingen, 2015
2015
Cited alongside, same era.
D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” in Proceedings of the 3rd International Conference on Learning Representations, San Diego, CA, USA , 2015, pp. 1–15
2015
Cited alongside, same era.
F. Yamaguchi, A. Maier, H. Gascon, and K. Rieck, “Automatic inference of search patterns for taint-style vulnerabilities,” in Proceedings of 2015 IEEE Symposium on Security and Privacy, San Jose, CA, USA , 2015, pp. 797–812
2015
Cited alongside, same era.
Z. Li, D. Zou, S. Xu, H. Jin, H. Qi, and J. Hu, “VulPecker: An automated vulnerability detection system based on code similarity analysis,” in Proceedings of the 32nd Annual Conference on Computer Security Applications, Los Angeles, CA, USA , 2016, pp. 201–213
2016
Cited alongside, same era.
G. Grieco, G. L. Grinblat, L. C. Uzal, S. Rawat, J. Feist, and L. Mounier, “Toward large-scale vulnerability discovery using machine learning,” in Proceedings of the 6th ACM on Conference on Data and Application Security and Privacy, New Orleans, LA, USA , 2016, pp. 85–96
2016
Cited alongside, same era.
M. White, M. Tufano, C. Vendome, and D. Poshyvanyk, “Deep learning code fragments for code clone detection,” in Proceedings of the 31st IEEE/ACM International Conference on Automated Software Engineering, Singapore , 2016, pp. 87–98
2016
Cited alongside, same era.
S. Wang, T. Liu, and L. Tan, “Automatically learning semantic features for defect prediction,” in Proceedings of the 38th International Conference on Software Engineering, Austin, TX, USA , 2016, pp. 297–308
2016
Cited alongside, same era.
A. Shrivastava, A. Gupta, and R. B. Girshick, “Training region-based object detectors with online hard example mining,” in Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA , 2016, pp. 761–769
2016
Cited alongside, same era.
S. M. Ghaffarian and H. R. Shahriari, “Software vulnerability analysis and discovery using machine-learning and data-mining techniques: A survey,” ACM Comput. Surv. , vol. 50, no. 4, pp. 56:1–56:36, 2017
2017
Later among the works it cites.
“CVE,” 2018, http://cve.mitre.org/
2018
Closest in time.
“FlawFinder,” 2018, http://www.dwheeler.com/flawfinder
2018
Closest in time.
“Checkmarx,” 2018, https://www.checkmarx.com/
2018
Closest in time.
Z. Li, D. Zou, S. Xu, X. Ou, H. Jin, S. Wang, Z. Deng, and Y. Zhong, “VulDeePecker: A deep learning-based system for vulnerability detection,” in Proceedings of the 25th Annual Network and Distributed System Security Symposium, San Diego, CA, USA , 2018, pp. 1–15
2018
Closest in time.
Q. Geng, Z. Zhou, and X. Cao, “Survey of recent progress in semantic image segmentation with CNNs,” Sci. China-Inf. Sci. , vol. 61, no. 5, pp. 051 101:1–051 101:18, 2018
2018
Closest in time.
“NVD,” 2018, https://nvd.nist.gov/
2018
Closest in time.
“Software assurance reference dataset,” 2018, https://samate.nist.gov/SRD/index.php
2018
Closest in time.
“Common Weakness Enumeration,” 2018, http://cwe.mitre.org/
2018
Closest in time.
“word2vec,” 2018, http://radimrehurek.com/gensim/models/word2vec.html
2018
Closest in time.
W. L. Caldas, J. P. P. Gomes, and D. P. P. Mesquita, “Fast co-mlm: An efficient semi-supervised co-training method based on the minimal learning machine,” New Generation Comput. , vol. 36, no. 1, pp. 41–58, 2018
2018
Closest in time.
D. Zou, S. Wang, S. Xu, Z. Li, and H. Jin, “ μ \mu VulDeePecker: A deep learning-based system for multiclass vulnerability detection,” IEEE Trans. Dependable Sec. Comput. , vol. PP, pp. 1–1, 2019
2019
Closest in time.