The use of machine learning with signal- and NLP processing of source code to fingerprint, detect, and classify vulnerabilities and weaknesses with MARFCAT
Cryptography and Security2011-11-08v6Programming Languages
We present a machine learning approach to static code analysis and fingerprinting for weaknesses related to security, software engineering, and others using the open-source MARF framework and the MARFCAT application based on it for the NIST's SATE2010 static analysis tool exposition workshop found at http://samate.nist.gov/SATE2010Workshop.html
@article{arxiv.1010.2511,
title = {The use of machine learning with signal- and NLP processing of source code to fingerprint, detect, and classify vulnerabilities and weaknesses with MARFCAT},
author = {Serguei A. Mokhov},
journal= {arXiv preprint arXiv:1010.2511},
year = {2011}
}
Comments
33 pages, 11 tables; some results presented at SATE2010; NIST, October 2011; shorter version of v5 appears in the NIST technical report at http://samate.nist.gov/docs/NIST_Special_Publication_500-283.pdf#page=49 where its presentation is found at http://samate.nist.gov/docs/SATE2010/SATE10_13_Marfcat_Mokhov.pdf and the MARFCAT OSS release at http://sourceforge.net/projects/marf/files/Applications/MARFCAT/