An Optimized Static Propositional Function Model to Detect Software Vulnerability

3Citations
Citations of this article
13Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Due to the lack of appropriate theory to accurately characterize vulnerabilities, the current static detection technologies have two key challenges, i.e., limited applicability, and the problem of state space explosion. In this paper, we put forward a static detection model based on the proposition function. Furthermore, a new program intermediate representation called Vulnerability Executable Path Set (VEPS) is proposed to optimize our model which compresses the program state space distinctly. In addition, in order to confirm the reliability of the static detection model, we conduct three terms of contrast experiments to estimate the results with the vulnerability disclosed by NIST. The results obtained from extensive experiments show that the proposed model effectively detects more Wireshark bugs than NIST, and reveals a higher detection efficiency than FindBugs.

Cite

CITATION STYLE

APA

Han, L., Zhou, M., Qian, Y., Fu, C., & Zou, D. (2019). An Optimized Static Propositional Function Model to Detect Software Vulnerability. IEEE Access, 7, 143499–143510. https://doi.org/10.1109/ACCESS.2019.2943896

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free