Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

SMINER: Detecting Unrestricted and Misimplemented Behaviors of Software Systems Based on Unit Test Cases

Full metadata record
DC Field Value Language
dc.contributor.authorSim, Kyungmin-
dc.contributor.authorYi, Jeong Hyun-
dc.contributor.authorCho, Haehyun-
dc.date.accessioned2023-06-07T06:40:10Z-
dc.date.available2023-06-07T06:40:10Z-
dc.date.created2023-06-02-
dc.date.issued2023-03-
dc.identifier.issn1546-2218-
dc.identifier.urihttp://scholarworks.bwise.kr/ssu/handle/2018.sw.ssu/43961-
dc.description.abstractDespite the advances in automated vulnerability detection approaches, security vulnerabilities caused by design flaws in software systems are continuously appearing in real-world systems. Such security design flaws can bring unrestricted and misimplemented behaviors of a system and can lead to fatal vulnerabilities such as remote code execution or sensitive data leakage. Therefore, it is an essential task to discover unrestricted and misimplemented behaviors of a system. However, it is a daunting task for security experts to discover such vulnerabilities in advance because it is timeconsuming and error-prone to analyze the whole code in detail. Also, most of the existing vulnerability detection approaches still focus on detecting memory corruption bugs because these bugs are the dominant root cause of software vulnerabilities. This paper proposes SMINER, a novel approach that discovers vulnerabilities caused by unrestricted and misimplemented behaviors. SMINER first collects unit test cases for the target system from the official repository. Next, preprocess the collected code fragments. SMINER uses pre-processed data to show the security policies that can occur on the target system and creates a test case for security policy testing. To demonstrate the effectiveness of SMINER, this paper evaluates SMINER against Robot Operating System (ROS), a real-world system used for intelligent robots in Amazon and controlling satellites in National Aeronautics and Space Administration (NASA). From the evaluation, we discovered two real-world vulnerabilities in ROS.-
dc.language영어-
dc.language.isoen-
dc.publisherTECH SCIENCE PRESS-
dc.relation.isPartOfCMC-COMPUTERS MATERIALS & CONTINUA-
dc.titleSMINER: Detecting Unrestricted and Misimplemented Behaviors of Software Systems Based on Unit Test Cases-
dc.typeArticle-
dc.identifier.doi10.32604/cmc.2023.036695-
dc.type.rimsART-
dc.identifier.bibliographicCitationCMC-COMPUTERS MATERIALS & CONTINUA, v.75, no.2, pp.3257 - 3274-
dc.description.journalClass1-
dc.identifier.wosid000975791200001-
dc.identifier.scopusid2-s2.0-85154533575-
dc.citation.endPage3274-
dc.citation.number2-
dc.citation.startPage3257-
dc.citation.titleCMC-COMPUTERS MATERIALS & CONTINUA-
dc.citation.volume75-
dc.contributor.affiliatedAuthorYi, Jeong Hyun-
dc.contributor.affiliatedAuthorCho, Haehyun-
dc.type.docTypeArticle-
dc.description.isOpenAccessY-
dc.subject.keywordAuthorSecurity vulnerability-
dc.subject.keywordAuthortest case generation-
dc.subject.keywordAuthorsecurity policy test-
dc.subject.keywordAuthorrobot operating system-
dc.subject.keywordAuthorvulnerability assessment-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalResearchAreaMaterials Science-
dc.relation.journalWebOfScienceCategoryComputer Science, Information Systems-
dc.relation.journalWebOfScienceCategoryMaterials Science, Multidisciplinary-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
Files in This Item
There are no files associated with this item.
Appears in
Collections
College of Information Technology > School of Software > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher CHO, HAEHYUN photo

CHO, HAEHYUN
College of Information Technology (School of Software)
Read more

Altmetrics

Total Views & Downloads

BROWSE