Case study · Research Project
VCIPR — Vulnerability Detection at Function Level
ResearchSoftware Security
- Problem
- Function-level vulnerabilities (e.g. buffer overflows in C/C++) are easily copied across software projects without triggering file-level matches.
- Built
- Extracted normalized function token streams and calculated patch diff signatures to identify vulnerable code variants.
- Outcome
- Published at IEEE ICST 2019, showing precise function-level vulnerability matching upon patch release.
Overview
A scalable, token-based and language-independent tool for detecting vulnerable and unpatched code fragments at function-level granularity.
Want something like this built?
I take on serious projects through Megicode — from scope to shipped product. Or browse the rest of the proof first.