Theme Icon
Case study · Research Project

Patch Analysis and Vulnerability Research

ResearchSoftware Security
Problem
Vulnerability research requires standardized, multi-granularity code benchmarks to benchmark detection tools fairly.
Built
Parsed historical CVE security commits (git diffs), mapping before-and-after patch fragments with corresponding CWE classifications.
Outcome
Published benchmark methodology in IET Information Security (2020) for reproducible software security evaluations.

Overview

A structured benchmark that traces open-source security patches and extracts vulnerable source code at function, file, and component granularity for repeatable security assessment.

Want something like this built?

I take on serious projects through Megicode — from scope to shipped product. Or browse the rest of the proof first.