Theme Icon
Case study · Research Project

VCIPR — Vulnerability Detection at Function Level

ResearchSoftware Security
Problem
Function-level vulnerabilities (e.g. buffer overflows in C/C++) are easily copied across software projects without triggering file-level matches.
Built
Extracted normalized function token streams and calculated patch diff signatures to identify vulnerable code variants.
Outcome
Published at IEEE ICST 2019, showing precise function-level vulnerability matching upon patch release.

Overview

A scalable, token-based and language-independent tool for detecting vulnerable and unpatched code fragments at function-level granularity.

Want something like this built?

I take on serious projects through Megicode — from scope to shipped product. Or browse the rest of the proof first.