Case study · Research Project
Patch Analysis and Vulnerability Research
ResearchSoftware Security
- Problem
- Vulnerability research requires standardized, multi-granularity code benchmarks to benchmark detection tools fairly.
- Built
- Parsed historical CVE security commits (git diffs), mapping before-and-after patch fragments with corresponding CWE classifications.
- Outcome
- Published benchmark methodology in IET Information Security (2020) for reproducible software security evaluations.
Overview
A structured benchmark that traces open-source security patches and extracts vulnerable source code at function, file, and component granularity for repeatable security assessment.
Want something like this built?
I take on serious projects through Megicode — from scope to shipped product. Or browse the rest of the proof first.