Matches in SemOpenAlex for { <https://semopenalex.org/work/W4289744595> ?p ?o ?g. }
Showing items 1 to 71 of
71
with 100 items per page.
- W4289744595 abstract "Testing is the most widely employed method to find vulnerabilities in real-world software programs. Compositional analysis, based on symbolic execution, is an automated testing method to find vulnerabilities in medium- to large-scale programs consisting of many interacting components. However, existing compositional analysis frameworks do not assess the severity of reported vulnerabilities. In this paper, we present a framework to analyze vulnerabilities discovered by an existing compositional analysis tool and assign CVSS3 (Common Vulnerability Scoring System v3.0) scores to them, based on various heuristics such as interaction with related components, ease of reachability, complexity of design and likelihood of accepting unsanitized input. By analyzing vulnerabilities reported with CVSS3 scores in the past, we train simple machine learning models. By presenting our interactive framework to developers of popular open-source software and other security experts, we gather feedback on our trained models and further improve the features to increase the accuracy of our predictions. By providing qualitative (based on community feedback) and quantitative (based on prediction accuracy) evidence from 21 open-source programs, we show that our severity prediction framework can effectively assist developers with assessing vulnerabilities." @default.
- W4289744595 created "2022-08-04" @default.
- W4289744595 creator A5002011805 @default.
- W4289744595 creator A5038593290 @default.
- W4289744595 creator A5063496418 @default.
- W4289744595 creator A5085798072 @default.
- W4289744595 date "2018-07-24" @default.
- W4289744595 modified "2023-10-16" @default.
- W4289744595 title "Automatically Assessing Vulnerabilities Discovered by Compositional Analysis" @default.
- W4289744595 doi "https://doi.org/10.48550/arxiv.1807.09160" @default.
- W4289744595 hasPublicationYear "2018" @default.
- W4289744595 type Work @default.
- W4289744595 citedByCount "0" @default.
- W4289744595 crossrefType "posted-content" @default.
- W4289744595 hasAuthorship W4289744595A5002011805 @default.
- W4289744595 hasAuthorship W4289744595A5038593290 @default.
- W4289744595 hasAuthorship W4289744595A5063496418 @default.
- W4289744595 hasAuthorship W4289744595A5085798072 @default.
- W4289744595 hasBestOaLocation W42897445951 @default.
- W4289744595 hasConcept C111919701 @default.
- W4289744595 hasConcept C115903868 @default.
- W4289744595 hasConcept C119857082 @default.
- W4289744595 hasConcept C124101348 @default.
- W4289744595 hasConcept C127705205 @default.
- W4289744595 hasConcept C136643341 @default.
- W4289744595 hasConcept C199360897 @default.
- W4289744595 hasConcept C22680326 @default.
- W4289744595 hasConcept C2522767166 @default.
- W4289744595 hasConcept C2777904410 @default.
- W4289744595 hasConcept C29983905 @default.
- W4289744595 hasConcept C38652104 @default.
- W4289744595 hasConcept C41008148 @default.
- W4289744595 hasConcept C527648132 @default.
- W4289744595 hasConcept C62913178 @default.
- W4289744595 hasConcept C80444323 @default.
- W4289744595 hasConcept C95713431 @default.
- W4289744595 hasConcept C97686452 @default.
- W4289744595 hasConceptScore W4289744595C111919701 @default.
- W4289744595 hasConceptScore W4289744595C115903868 @default.
- W4289744595 hasConceptScore W4289744595C119857082 @default.
- W4289744595 hasConceptScore W4289744595C124101348 @default.
- W4289744595 hasConceptScore W4289744595C127705205 @default.
- W4289744595 hasConceptScore W4289744595C136643341 @default.
- W4289744595 hasConceptScore W4289744595C199360897 @default.
- W4289744595 hasConceptScore W4289744595C22680326 @default.
- W4289744595 hasConceptScore W4289744595C2522767166 @default.
- W4289744595 hasConceptScore W4289744595C2777904410 @default.
- W4289744595 hasConceptScore W4289744595C29983905 @default.
- W4289744595 hasConceptScore W4289744595C38652104 @default.
- W4289744595 hasConceptScore W4289744595C41008148 @default.
- W4289744595 hasConceptScore W4289744595C527648132 @default.
- W4289744595 hasConceptScore W4289744595C62913178 @default.
- W4289744595 hasConceptScore W4289744595C80444323 @default.
- W4289744595 hasConceptScore W4289744595C95713431 @default.
- W4289744595 hasConceptScore W4289744595C97686452 @default.
- W4289744595 hasLocation W42897445951 @default.
- W4289744595 hasOpenAccess W4289744595 @default.
- W4289744595 hasPrimaryLocation W42897445951 @default.
- W4289744595 hasRelatedWork W1580192808 @default.
- W4289744595 hasRelatedWork W2135328446 @default.
- W4289744595 hasRelatedWork W2380031640 @default.
- W4289744595 hasRelatedWork W2383958993 @default.
- W4289744595 hasRelatedWork W2392272505 @default.
- W4289744595 hasRelatedWork W2884293495 @default.
- W4289744595 hasRelatedWork W2949297114 @default.
- W4289744595 hasRelatedWork W3095596037 @default.
- W4289744595 hasRelatedWork W3165728054 @default.
- W4289744595 hasRelatedWork W4287631894 @default.
- W4289744595 isParatext "false" @default.
- W4289744595 isRetracted "false" @default.
- W4289744595 workType "article" @default.