Patchworking: Exploring the code changes induced by vulnerability fixing activities

Information and Software Technology(2022)

引用 5|浏览14
暂无评分
摘要
•Vulnerabilities of the same types are often resolved by applying similar code transformations.•Security patches to CWE-264 vulnerabilities involve more files than the other vulnerabilities.•Vulnerabilities caused by improper data handling entail the addition of new methods.•Vulnerabilities caused by improper input/output sanitization require the addition of new conditional branches.
更多
查看译文
关键词
Software vulnerabilities,Software maintenance,Empirical study
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要