{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T19:11:56Z","timestamp":1782587516308,"version":"3.54.5"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"12","license":[{"start":{"date-parts":[[2022,11,12]],"date-time":"2022-11-12T00:00:00Z","timestamp":1668211200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,11,12]],"date-time":"2022-11-12T00:00:00Z","timestamp":1668211200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100003819","name":"Natural Science Foundation of Hubei Province","doi-asserted-by":"publisher","award":["2020BAB116"],"award-info":[{"award-number":["2020BAB116"]}],"id":[{"id":"10.13039\/501100003819","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Ningbo Cixing Co.","award":["2021Z069"],"award-info":[{"award-number":["2021Z069"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2023,6]]},"DOI":"10.1007\/s10489-022-04214-8","type":"journal-article","created":{"date-parts":[[2022,11,12]],"date-time":"2022-11-12T08:02:34Z","timestamp":1668240154000},"page":"15204-15221","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["BovdGFE: buffer overflow vulnerability detection based on graph feature extraction"],"prefix":"10.1007","volume":"53","author":[{"given":"Xinghang","family":"Lv","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tao","family":"Peng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5275-3408","authenticated-orcid":false,"given":"Jia","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junping","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinrong","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruhan","family":"He","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Minghua","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenli","family":"Cao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,11,12]]},"reference":[{"key":"4214_CR1","doi-asserted-by":"crossref","unstructured":"Liang H, Wang L, Wu D, Xu J (2016) Mlsa: a static bugs analysis tool based on llvm ir. In: 2016 17th IEEE\/ACIS international conference on software engineering, artificial intelligence, networking and parallel\/distributed computing (SNPD), IEEE, pp 407\u2013412","DOI":"10.1109\/SNPD.2016.7515932"},{"issue":"5","key":"4214_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11432-015-5422-7","volume":"60","author":"Z Fang","year":"2017","unstructured":"Fang Z, Liu Q, Zhang Y, Wang K, Wang Z, Wu Q (2017) A static technique for detecting input validation vulnerabilities in android apps. Sci China Inf Sci 60(5):1\u201316","journal-title":"Sci China Inf Sci"},{"key":"4214_CR3","doi-asserted-by":"crossref","unstructured":"Kim S, Woo S, Lee H, Oh H (2017) Vuddy: A scalable approach for vulnerable code clone discovery. In: 2017 IEEE symposium on security and privacy (SP), IEEE, pp 595\u2013614","DOI":"10.1109\/SP.2017.62"},{"key":"4214_CR4","doi-asserted-by":"crossref","unstructured":"Li Z, Zou D, Xu S, Jin H, Qi H, Hu J (2016) Vulpecker: an automated vulnerability detection system based on code similarity analysis. In: Proceedings of the 32nd annual conference on computer security applications, pp 201\u2013213","DOI":"10.1145\/2991079.2991102"},{"key":"4214_CR5","unstructured":"Cadar C, Dunbar D, Engler D (2008) KLEE: Unassisted and automatic generation of high-coverage tests for complex systems programs. In: Proc. operating system design and implementation, pp 209\u2013224"},{"key":"4214_CR6","doi-asserted-by":"crossref","unstructured":"Yamaguchi F, Lottmann M, Rieck K (2012) Generalized vulnerability extrapolation using abstract syntax trees. In: Proceedings of the 28th annual computer security applications conference, pp 359\u2013368","DOI":"10.1145\/2420950.2421003"},{"issue":"1","key":"4214_CR7","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1145\/2090147.2094081","volume":"10","author":"P Godefroid","year":"2012","unstructured":"Godefroid P, Levin MY, Molnar D (2012) Sage: whitebox fuzzing for security testing: sage has had a remarkable impact at microsoft. Queue 10(1):20","journal-title":"Queue"},{"issue":"11","key":"4214_CR8","doi-asserted-by":"publisher","first-page":"2312","DOI":"10.1109\/TSE.2019.2946563","volume":"47","author":"VJ Man\u00e8s","year":"2019","unstructured":"Man\u00e8s VJ, Han H, Han C, Cha SK, Egele M, Schwartz EJ, Woo M (2019) The art, science, and engineering of fuzzing: a survey. IEEE Trans Softw Eng 47(11):2312\u20132331","journal-title":"IEEE Trans Softw Eng"},{"key":"4214_CR9","doi-asserted-by":"crossref","unstructured":"Peng H, Shoshitaishvili Y, Payer M (2018) T-fuzz: fuzzing by program transformation. In: 2018 IEEE symposium on security and privacy (SP), IEEE, pp 697\u2013710","DOI":"10.1109\/SP.2018.00056"},{"key":"4214_CR10","doi-asserted-by":"crossref","unstructured":"She D, Chen Y, Shah A, Ray B, Jana S (2020) Neutaint: Efficient dynamic taint analysis with neural networks. In: 2020 IEEE symposium on security and privacy (SP), IEEE, pp 1527\u20131543","DOI":"10.1109\/SP40000.2020.00022"},{"key":"4214_CR11","first-page":"152","volume":"107139","author":"W Niu","year":"2020","unstructured":"Niu W, Zhang X, Du X, Zhao L, Cao R, Guizani M (2020) A deep learning based static taint analysis approach for iot software vulnerability location. Measurement 107139:152","journal-title":"Measurement"},{"key":"4214_CR12","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1016\/j.compeleceng.2018.11.004","volume":"73","author":"P Bojovi\u0107","year":"2019","unstructured":"Bojovi\u0107 P, Ba\u0161i\u010devi\u0107 I, Ocovaj S, Popovi\u0107 M (2019) A practical approach to detection of distributed denial-of-service attacks using a hybrid detection method. Comput Electr Eng 73:84\u201396","journal-title":"Comput Electr Eng"},{"issue":"04","key":"4214_CR13","doi-asserted-by":"publisher","first-page":"190","DOI":"10.36548\/jismac.2020.4.002","volume":"2","author":"S Smys","year":"2020","unstructured":"Smys S, Basar A, Wang H, et al. (2020) Hybrid intrusion detection system for internet of things (iot). J ISMAC 2(04):190\u2013199","journal-title":"J ISMAC"},{"issue":"4","key":"4214_CR14","first-page":"13","volume":"5","author":"Z Chen","year":"2020","unstructured":"Chen Z, Zou D, Li Z, Jin H (2020) Intelligent vulnerability detection system based on abstract syntax tree. J Inf Secur 5(4):13","journal-title":"J Inf Secur"},{"issue":"8","key":"4214_CR15","doi-asserted-by":"publisher","first-page":"6265","DOI":"10.1007\/s10489-021-02220-w","volume":"51","author":"T Wang","year":"2021","unstructured":"Wang T, Guo J, Wu Z, Xu T (2021) Ifta: iterative filtering by using tf-aicl algorithm for chinese encyclopedia knowledge refinement. Appl Intell 51(8):6265\u20136293","journal-title":"Appl Intell"},{"key":"4214_CR16","doi-asserted-by":"publisher","first-page":"245","DOI":"10.1016\/j.eswa.2016.09.009","volume":"66","author":"K Chen","year":"2016","unstructured":"Chen K, Zhang Z, Long J, Zhang H (2016) Turning from tf-idf to tf-igm for term weighting in text classification. Expert Syst Appl 66:245\u2013260","journal-title":"Expert Syst Appl"},{"issue":"4","key":"4214_CR17","doi-asserted-by":"publisher","first-page":"2244","DOI":"10.1109\/TDSC.2021.3051525","volume":"19","author":"Z Li","year":"2021","unstructured":"Li Z, Zou D, Xu S, Jin H, Zhu Y, Chen Z (2021) Sysevr: a framework for using deep learning to detect software vulnerabilities. IEEE Trans Dependable Secure Comput 19(4):2244\u20132258","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"4214_CR18","doi-asserted-by":"crossref","unstructured":"Nandi A, Mandal A, Atreja S, Dasgupta GB, Bhattacharya S (2016) Anomaly detection using program control flow graph mining from execution logs. In: Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining, pp 215\u2013224","DOI":"10.1145\/2939672.2939712"},{"key":"4214_CR19","doi-asserted-by":"publisher","first-page":"11382","DOI":"10.1109\/ACCESS.2022.3146413","volume":"10","author":"J Wang","year":"2022","unstructured":"Wang J, Park S, Park CS (2022) Spatial data dependence graph based pre-rtl simulator for convolutional neural network dataflows. IEEE Access 10:11382\u201311403","journal-title":"IEEE Access"},{"key":"4214_CR20","doi-asserted-by":"crossref","unstructured":"Zhang J, Wang X, Zhang H, Sun H, Wang K, Liu X (2019) A novel neural source code representation based on abstract syntax tree. In: 2019 IEEE\/ACM 41st international conference on software engineering (ICSE), IEEE, pp 783\u2013794","DOI":"10.1109\/ICSE.2019.00086"},{"issue":"2","key":"4214_CR21","doi-asserted-by":"publisher","first-page":"1337","DOI":"10.1109\/COMST.2020.2971757","volume":"22","author":"K Ullah","year":"2020","unstructured":"Ullah K, Rashid I, Afzal H, Iqbal MMW, Bangash YA, Abbas H (2020) Ss7 vulnerabilities\u2014a survey and implementation of machine learning vs rule based filtering for detection of ss7 network attacks. IEEE Commun Surv Tutor 22(2):1337\u20131371","journal-title":"IEEE Commun Surv Tutor"},{"key":"4214_CR22","doi-asserted-by":"crossref","unstructured":"Croft R, Newlands D, Chen Z, Babar MA (2021) An empirical study of rule-based and learning-based approaches for static application security testing. In: Proceedings of the 15th ACM\/IEEE international symposium on empirical software engineering and measurement (ESEM), pp 1\u201312","DOI":"10.1145\/3475716.3475781"},{"key":"4214_CR23","doi-asserted-by":"crossref","unstructured":"Du X, Chen B, Li Y, Guo J, Zhou Y, Liu Y, Jiang Y (2019) Leopard: identifying vulnerable code for vulnerability assessment through program metrics. In: 2019 IEEE\/ACM 41st international conference on software engineering (ICSE), IEEE, pp 60\u201371","DOI":"10.1109\/ICSE.2019.00024"},{"key":"4214_CR24","doi-asserted-by":"crossref","unstructured":"Li Z, Zou D, Xu S, Ou X, Jin H, Wang S, Deng Z, Zhong Y (2018) Vuldeepecker: a deep learning-based system for vulnerability detection. In: Proceedings of the 25th annual network and distributed system security symposium, San Diego, California, USA","DOI":"10.14722\/ndss.2018.23158"},{"key":"4214_CR25","doi-asserted-by":"crossref","unstructured":"Gan S, Zhang C, Qin X, Tu X, Li K, Pei Z, Chen Z (2018) Collafl: Path sensitive fuzzing. In: 2018 IEEE symposium on security and privacy (SP), IEEE, pp 679\u2013696","DOI":"10.1109\/SP.2018.00040"},{"key":"4214_CR26","doi-asserted-by":"crossref","unstructured":"He J, Balunovi\u0107 M, Ambroladze N, Tsankov P, Vechev M (2019) Learning to fuzz from symbolic execution with application to smart contracts. In: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, pp 531\u2013548","DOI":"10.1145\/3319535.3363230"},{"key":"4214_CR27","doi-asserted-by":"crossref","unstructured":"Mossberg M, Manzano F, Hennenfent E, Groce A, Grieco G, Feist J, Brunson T, Dinaburg A (2019) Manticore: A user-friendly symbolic execution framework for binaries and smart contracts. In: 2019 34th IEEE\/ACM international conference on automated software engineering (ASE), IEEE, pp 1186\u20131189","DOI":"10.1109\/ASE.2019.00133"},{"key":"4214_CR28","unstructured":"Poeplau S, Francillon A (2020) Symbolic execution with {symCC}: Don\u2019t interpret, compile!. In: 29Th USENIX security symposium (USENIX security 20), pp 181\u2013198"},{"key":"4214_CR29","doi-asserted-by":"crossref","unstructured":"Sun P, Garcia L, Salles-Loustau G, Zonouz S (2020) Hybrid firmware analysis for known mobile and iot security vulnerabilities. In: 2020 50th Annual IEEE\/IFIP international conference on dependable systems and networks (DSN), IEEE, pp 373\u2013384","DOI":"10.1109\/DSN48063.2020.00053"},{"issue":"3","key":"4214_CR30","doi-asserted-by":"publisher","first-page":"2154","DOI":"10.1109\/TII.2019.2942800","volume":"16","author":"S Liu","year":"2019","unstructured":"Liu S, Dibaei M, Tai Y, Chen C, Zhang J, Xiang Y (2019) Cyber vulnerability intelligence for internet of things binary. IEEE Trans Ind Inf 16(3):2154\u20132163","journal-title":"IEEE Trans Ind Inf"},{"issue":"19","key":"4214_CR31","doi-asserted-by":"publisher","first-page":"4086","DOI":"10.3390\/app9194086","volume":"9","author":"Y Lee","year":"2019","unstructured":"Lee Y, Kwon H, Choi S-H, Lim S-H, Baek SH, Park K-W (2019) Instruction2vec: efficient preprocessor of assembly code to detect software weakness with cnn. Appl Sci 9(19):4086","journal-title":"Appl Sci"},{"key":"4214_CR32","first-page":"108","volume":"102286","author":"H Yan","year":"2021","unstructured":"Yan H, Luo S, Pan L, Zhang Y (2021) Han-bsvd: a hierarchical attention network for binary software vulnerability detection. Comput Secur 102286:108","journal-title":"Comput Secur"},{"key":"4214_CR33","first-page":"136","volume":"106576","author":"S Cao","year":"2021","unstructured":"Cao S, Sun X, Bo L, Wei Y, Li B (2021) Bgnn4vd: constructing bidirectional graph neural-network for vulnerability detection. Inf Softw Technol 106576:136","journal-title":"Inf Softw Technol"},{"key":"4214_CR34","doi-asserted-by":"publisher","first-page":"106809","DOI":"10.1016\/j.infsof.2021.106809","volume":"144","author":"L Wartschinski","year":"2022","unstructured":"Wartschinski L, Noller Y, Vogel T, Kehrer T, Grunske L (2022) Vudenc: vulnerability detection with deep learning on a natural codebase for python. Inf Softw Technol 144:106809","journal-title":"Inf Softw Technol"},{"key":"4214_CR35","doi-asserted-by":"publisher","first-page":"102823","DOI":"10.1016\/j.cose.2022.102823","volume":"121","author":"W Guo","year":"2022","unstructured":"Guo W, Fang Y, Huang C, Ou H, Lin C, Guo Y (2022) Hyvuldect: a hybrid semantic vulnerability mining system based on graph neural network. Comput Secur 121:102823","journal-title":"Comput Secur"},{"key":"4214_CR36","doi-asserted-by":"publisher","first-page":"111450","DOI":"10.1016\/j.jss.2022.111450","volume":"193","author":"S Salimi","year":"2022","unstructured":"Salimi S, Kharrazi M (2022) Vulslicer: vulnerability detection through code slicing. J Syst Softw 193:111450","journal-title":"J Syst Softw"},{"key":"4214_CR37","doi-asserted-by":"crossref","unstructured":"Weber M, Engert M, Schaffer N, Weking J, Krcmar H (2022) Organizational capabilities for ai implementation\u2014coping with inscrutability and data dependency in ai. Inf Syst Front :1\u201321","DOI":"10.1007\/s10796-022-10297-y"},{"issue":"5","key":"4214_CR38","doi-asserted-by":"publisher","first-page":"1829","DOI":"10.3390\/s22051829","volume":"22","author":"J Huang","year":"2022","unstructured":"Huang J, Zhou K, Xiong A, Li D (2022) Smart contract vulnerability detection model based on multi-task learning. Sensors 22(5):1829","journal-title":"Sensors"},{"issue":"11","key":"4214_CR39","first-page":"3404","volume":"31","author":"X Duan","year":"2020","unstructured":"Duan X, Wu J, Luo T, Yang M, Wu Y (2020) A vulnerability mining approach based on code attribute graph and attentional bi-directional lstm. J Softw 31(11):3404\u20133420","journal-title":"J Softw"},{"key":"4214_CR40","doi-asserted-by":"crossref","unstructured":"Mou L, Jin Z (2018) Tbcnn for dependency trees in natural language processing. In: Tree-based convolutional neural networks, pp 73\u201389","DOI":"10.1007\/978-981-13-1870-2_6"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-022-04214-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-022-04214-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-022-04214-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,1]],"date-time":"2023-06-01T03:52:37Z","timestamp":1685591557000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-022-04214-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,12]]},"references-count":40,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2023,6]]}},"alternative-id":["4214"],"URL":"https:\/\/doi.org\/10.1007\/s10489-022-04214-8","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,12]]},"assertion":[{"value":"26 September 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 November 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}