Maestro: A platform for benchmarking automatic program repair tools on software vulnerabilities

9Citations
Citations of this article
16Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Automating the repair of vulnerabilities is emerging in the field of software security. Previous efforts have leveraged Automated Program Repair (APR) for the task. Reproducible pipelines of repair tools on vulnerability benchmarks can promote advances in the field, such as new repair techniques. We propose Maestro, a decentralized platform with RESTful APIs for performing automated software vulnerability repair. Our platform connects benchmarks of vulnerabilities with APR tools for performing controlled experiments. It also promotes fair comparisons among different APR tools. We compare the performance of Maestro with previous studies on four APR tools in finding repairs for ten projects. Our execution time results indicate an overhead of 23 seconds for projects in C and a reduction of 14 seconds for Java projects. We introduce an agnostic platform for vulnerability repair with preliminary tools/datasets for both C and Java. Maestro is modular and can accommodate tools, benchmarks, and repair workflows with dedicated plugins.

Author supplied keywords

Cite

CITATION STYLE

APA

Pinconschi, E., Bui, Q. C., Abreu, R., Adão, P., & Scandariato, R. (2022). Maestro: A platform for benchmarking automatic program repair tools on software vulnerabilities. In ISSTA 2022 - Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis (pp. 789–792). Association for Computing Machinery, Inc. https://doi.org/10.1145/3533767.3543291

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free