Matches in SemOpenAlex for { <https://semopenalex.org/work/W2960485560> ?p ?o ?g. }
Showing items 1 to 66 of
66
with 100 items per page.
- W2960485560 abstract "The early discovery of security bugs in JavaScript (JS) engines is crucial for protecting Internet users from adversaries abusing zero-day vulnerabilities. Browser vendors, bug bounty hunters, and security researchers have been eager to find such security bugs by leveraging state-of-the-art fuzzers as well as their domain expertise. They report a bug when observing a crash after executing their JS test since a crash is an early indicator of a potential bug. However, it is difficult to identify whether such a crash indeed invokes security bugs in JS engines. Thus, unskilled bug reporters are unable to assess the security severity of their new bugs with JS engine crashes. Today, this classification of a reported security bug is completely manual, depending on the verdicts from JS engine vendors. We investigated the feasibility of applying various machine learning classifiers to determine whether an observed crash triggers a security bug. We designed and implemented CRScope, which classifies security and non-security bugs from given crash-dump files. Our experimental results on 766 crash instances demonstrate that CRScope achieved 0.85, 0.89, and 0.93 Area Under Curve (AUC) for Chakra, V8, and SpiderMonkey crashes, respectively. CRScope also achieved 0.84, 0.89, and 0.95 precision for Chakra, V8, and SpiderMonkey crashes, respectively. This outperforms the previous study and existing tools including Exploitable and AddressSanitizer. CRScope is capable of learning domain-specific expertise from the past verdicts on reported bugs and automatically classifying JS engine security bugs, which helps improve the scalable classification of security bugs." @default.
- W2960485560 created "2019-07-23" @default.
- W2960485560 creator A5030789750 @default.
- W2960485560 creator A5062570829 @default.
- W2960485560 creator A5082893706 @default.
- W2960485560 date "2019-07-02" @default.
- W2960485560 modified "2023-09-26" @default.
- W2960485560 title "An Empirical Study of Prioritizing JavaScript Engine Crashes via Machine Learning" @default.
- W2960485560 cites W1981109290 @default.
- W2960485560 cites W2068119731 @default.
- W2960485560 cites W2090094826 @default.
- W2960485560 cites W2096598529 @default.
- W2960485560 cites W2107316307 @default.
- W2960485560 cites W2113351233 @default.
- W2960485560 cites W2125587588 @default.
- W2960485560 cites W2130343490 @default.
- W2960485560 cites W2133108681 @default.
- W2960485560 cites W2145302217 @default.
- W2960485560 cites W2166336492 @default.
- W2960485560 cites W2297419069 @default.
- W2960485560 cites W2383417445 @default.
- W2960485560 cites W2519952770 @default.
- W2960485560 cites W2538458302 @default.
- W2960485560 cites W2775532270 @default.
- W2960485560 cites W2794283311 @default.
- W2960485560 cites W2807415350 @default.
- W2960485560 doi "https://doi.org/10.1145/3321705.3329840" @default.
- W2960485560 hasPublicationYear "2019" @default.
- W2960485560 type Work @default.
- W2960485560 sameAs 2960485560 @default.
- W2960485560 citedByCount "0" @default.
- W2960485560 crossrefType "proceedings-article" @default.
- W2960485560 hasAuthorship W2960485560A5030789750 @default.
- W2960485560 hasAuthorship W2960485560A5062570829 @default.
- W2960485560 hasAuthorship W2960485560A5082893706 @default.
- W2960485560 hasConcept C111472728 @default.
- W2960485560 hasConcept C120936955 @default.
- W2960485560 hasConcept C138885662 @default.
- W2960485560 hasConcept C154945302 @default.
- W2960485560 hasConcept C199360897 @default.
- W2960485560 hasConcept C41008148 @default.
- W2960485560 hasConcept C544833334 @default.
- W2960485560 hasConceptScore W2960485560C111472728 @default.
- W2960485560 hasConceptScore W2960485560C120936955 @default.
- W2960485560 hasConceptScore W2960485560C138885662 @default.
- W2960485560 hasConceptScore W2960485560C154945302 @default.
- W2960485560 hasConceptScore W2960485560C199360897 @default.
- W2960485560 hasConceptScore W2960485560C41008148 @default.
- W2960485560 hasConceptScore W2960485560C544833334 @default.
- W2960485560 hasLocation W29604855601 @default.
- W2960485560 hasOpenAccess W2960485560 @default.
- W2960485560 hasPrimaryLocation W29604855601 @default.
- W2960485560 hasRelatedWork W1146933715 @default.
- W2960485560 hasRelatedWork W2348410391 @default.
- W2960485560 hasRelatedWork W2349820628 @default.
- W2960485560 hasRelatedWork W2372902072 @default.
- W2960485560 hasRelatedWork W2388105295 @default.
- W2960485560 hasRelatedWork W2392834243 @default.
- W2960485560 hasRelatedWork W2484322599 @default.
- W2960485560 hasRelatedWork W2792037268 @default.
- W2960485560 hasRelatedWork W2978069623 @default.
- W2960485560 hasRelatedWork W4229928981 @default.
- W2960485560 isParatext "false" @default.
- W2960485560 isRetracted "false" @default.
- W2960485560 magId "2960485560" @default.
- W2960485560 workType "article" @default.