A new method to construct the software vulnerability model
Xiang Li, Jinfu Chen, Zhechao Lin, Zhang Lin, Zibin Wang, Minmin Zhou, Wanggen Xie
Abstract
Xiang Li, Jinfu Chen, Zhechao Lin, Zhang Lin, Zibin Wang, Minmin Zhou, Wanggen Xie
Abstract
With the development of information technology, software plays an increasingly important role in the process of social development. However, at the same time, the number of software vulnerabilities is growing, posing a threat to national security and social stability. Therefore, some scholars and research institutions are paying their attention to the study of software vulnerability. In this paper, we propose a new vulnerability model construction method by considering the vulnerability causes and characteristics. Firstly, the causes and characteristics of software vulnerability are analyzed, and a formal vulnerability model is also established. Based on the causes and characteristics of software vulnerability, we establish the vulnerability model using the extended chemical abstract machine and deduce the software vulnerability through a formal method. We verified the effectiveness and efficiency of the proposed model using software vulnerability datasets. In addition, a prototype system is also designed and implemented. Experimental results show that the proposed model is more effective than other methods in the detection of software vulnerabilities.
OpenAlex reports 6 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
With the development of information technology, software plays an increasingly important role in the process of social development. However, at the same time, the number of software vulnerabilities is growing, posing a threat to national security and social stability. Therefore, some scholars and research institutions are paying their attention to the study of software vulnerability. In this paper, we propose a new vulnerability model construction method by considering the vulnerability causes and characteristics. Firstly, the causes and characteristics of software vulnerability are analyzed, and a formal vulnerability model is also established. Based on the causes and characteristics of software vulnerability, we establish the vulnerability model using the extended chemical abstract machine and deduce the software vulnerability through a formal method. We verified the effectiveness and efficiency of the proposed model using software vulnerability datasets. In addition, a prototype system is also designed and implemented. Experimental results show that the proposed model is more effective than other methods in the detection of software vulnerabilities.
Key concepts: Vulnerability (computing), Vulnerability management, Computer science, Software, Construct (python library), Software security assurance, Software development, Computer security