Skip to content

Opening book details…

Can I read Dicos: Discovering Insecure Code Snippets from Stack Overflow Posts by Leveraging User Discussions on EtoBox?

Dicos: Discovering Insecure Code Snippets from Stack Overflow Posts by Leveraging User Discussions by Hyunji Hong; Seunghoon Woo; Heejo Lee is a scholarly article available to read on EtoBox.

What is Dicos: Discovering Insecure Code Snippets from Stack Overflow Posts by Leveraging User Discussions about?

Online Q&A fora such as Stack Overflow assist developers to solve their faced coding problems. Despite the advantages, Stack Overflow has the potential to provide insecure code snippets that, if reused, can compromise the security of the entire software. We present Dicos, an accurate approach by examining the change history of Stack Overflow posts for discovering insecure code snippets. When a security issue was detected in a post, the insecure code is fixed to be safe through user discussions, leaving a change history. Inspired by this process, Dicos first extracts the change history from the Stack Overflow post, and then analyzes the history whether it contains security patches, by utilizing pre-selected features that can effectively identify security patches. Finally, when such changes are detected, Dicos determines that the code snippet before applying the security patch is insecure. To evaluate Dicos, we collected 1,958,283 Stack Overflow posts tagged with C, C++, and Android. When we applied Dicos on the collected posts, Dicos discovered 12,458 insecure posts (i.e., 14,719 insecure code snippets) from the collected posts with 91% precision and 93% recall. We further confirmed

Author
Hyunji Hong; Seunghoon Woo; Heejo Lee
Publisher
ACM
Published
2021
Language
EN