3 ms·
End to End Prediction of Buffer Overruns from Code via Neural Memory Networks
- chatmasta 10y agoThis is really cool. I've spent some time thinking about a similar idea in the past [0]. My idea was to parse the CVE database for bugs in open source code, then identify the patches used to fix the bugs. From the patch data, you can get an efficient diff of what the "vulnerable" code looks like and what the "fix" for it looks like. You can then convert the code to abstract syntax tree or feed it to a static analysis engine to use as "signals" in training a machine learning algorithm. Then you can apply the machine learning algorithm to open source databases and identify possibly vulnerable code paths. Looks like this paper had success doing something similar. Awesome! [0] https://news.ycombinator.com/item?id=11573547 https://news.ycombinator.com/item?id=11573547
- bitwize 10y agoThe first thing it learns is to check if the source is in Rust and if so, vastly reduce the likelihood of a buffer overrun.
- wyldfire 10y agoGroan. Rust fanboy here, but c'mon. Are you a member of the "Rust Evangelism Strikeforce" (as seen at http://n-gate.com/ http://n-gate.com/)?
- Nomentatus 10y agoRust is a great thing, and by reducing the number of faults that need to be searched for, it would actually help this kind of AI do its thing, here, too. But Rust doesn't prevent every problem, and sometimes ya gotta go unsafe in Rust, at which point it would be nice to have a quick check on that code. So I think these are independent endeavors; both very worthy.