Zhongxu Yin1, *, Yiran Song2, Huiqin Chen3, Yan Cao4
CMC-Computers, Materials & Continua, Vol.63, No.2, pp. 1013-1029, 2020, DOI:10.32604/cmc.2020.09345
- 01 May 2020
Abstract Security-sensitive functions are the basis for building a taint-style vulnerability
model. Current approaches for extracting security-sensitive functions either don’t analyze
data flow accurately, or not conducting pattern analyzing of conditions, resulting in
higher false positive rate or false negative rate, which increased manual confirmation
workload. In this paper, we propose a security sensitive function mining approach based
on preconditon pattern analyzing. Firstly, we propose an enhanced system dependency
graph analysis algorithm for precisely extracting the conditional statements which check
the function parameters and conducting statistical analysis of the conditional statements
for selecting candidate security sensitive More >