Loading…
FloCon 2019 has ended
Wednesday, January 9 • 12:30pm - 1:00pm
Lunchtime Table Talk: Towards Security Defect Prediction with AI LIMITED

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Limited Capacity seats available

In this study, we investigate the limits of the current state of the art AI system for detecting buffer overflows and compare it with current static analysis engines. To do so, we developed a code generator, s-bAbI, capable of producing an arbitrarily large number of samples of controlled complexity. We found that the static analysis engines we examined have good precision, but poor recall. We found that the state of the art AI system, a memory network modeled after another present in the literature, can achieve similar performance to the static analysis engines, but requires an exhaustive amount of training data in order to do so.

Our work implies that there are three threads of future work: First, further developing static analysis engines to improve their recall against this minimally complex class of synthetic code as a lower bar than NIST’s more realistic code datasets (e.g. Juliet). Second, improving AI systems to the point were they can at least solve s-bAbI. And, third, increasing the complexity of s-bAbI to find the additional failure modes of improved static analysis engines and AI systems.

Attendees will Learn:
• the current state of the art in neural networks applied to code analysis
• some secure coding best practices
• how secure coding can improve using AI techniques

Speakers
avatar for Eliezer Kanal

Eliezer Kanal

Technical Manager, CERT Division - Software Engineering Institute
Eliezer Kanal is a technical manager at CERT who focuses on applying machine learning techniques to the cybersecurity domain. His team contributed to a wide variety of projects, including statistical visualization tools to assist with malware reverse engineering, metrics for the efficacy... Read More →


Wednesday January 9, 2019 12:30pm - 1:00pm EST
Fleur de Lis A 300 Bourbon St, New Orleans, LA 70130, USA

Attendees (4)