{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T02:28:12Z","timestamp":1760149692944,"version":"build-2065373602"},"reference-count":52,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2023,9,8]],"date-time":"2023-09-08T00:00:00Z","timestamp":1694131200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"RSF","award":["#23-21-00498"],"award-info":[{"award-number":["#23-21-00498"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Currently, enhancing the efficiency of vulnerability detection and assessment remains relevant. We investigate a new approach for the detection of vulnerabilities that can be used in cyber attacks and assess their severity for further effective responses based on an analysis of exploit source codes and real-time detection of features of their implementation. The key element of this approach is an exploit source code model. In this paper, to specify the model, we systematically analyze existing source code models, approaches to source code analysis in general, and exploits in particular in order to examine their advantages, applications, and challenges. Finally, we provide an initial specification of the proposed source code model.<\/jats:p>","DOI":"10.3390\/info14090497","type":"journal-article","created":{"date-parts":[[2023,9,8]],"date-time":"2023-09-08T07:57:17Z","timestamp":1694159837000},"page":"497","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["An Analytical Review of the Source Code Models for Exploit Analysis"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6707-9153","authenticated-orcid":false,"given":"Elena","family":"Fedorchenko","sequence":"first","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences (SPIIRAS), St. Petersburg Federal Research Center of the Russian Academy of Sciences (SPC RAS), 39, 14th Liniya, 199178 St. Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2923-4954","authenticated-orcid":false,"given":"Evgenia","family":"Novikova","sequence":"additional","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences (SPIIRAS), St. Petersburg Federal Research Center of the Russian Academy of Sciences (SPC RAS), 39, 14th Liniya, 199178 St. Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5727-653X","authenticated-orcid":false,"given":"Andrey","family":"Fedorchenko","sequence":"additional","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences (SPIIRAS), St. Petersburg Federal Research Center of the Russian Academy of Sciences (SPC RAS), 39, 14th Liniya, 199178 St. Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sergei","family":"Verevkin","sequence":"additional","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences (SPIIRAS), St. Petersburg Federal Research Center of the Russian Academy of Sciences (SPC RAS), 39, 14th Liniya, 199178 St. Petersburg, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,9,8]]},"reference":[{"key":"ref_1","unstructured":"Kitchenham, B.A. (2004). Procedures for Performing Systematic Reviews, Keele University."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"102817","DOI":"10.1016\/j.cose.2022.102817","article-title":"An empirical study of vulnerability discovery methods over the past ten years","volume":"120","author":"Cui","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.future.2021.11.030","article-title":"A study on malicious software behaviour analysis and detection techniques: Taxonomy, current trends and challenges","volume":"130","author":"Maniriho","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_4","first-page":"9867","article-title":"Tools and Techniques for Collection and Analysis of Internet-of-Things malware: A systematic state-of-art review","volume":"34","author":"Madan","year":"2022","journal-title":"J. King Saud Univ. Comput. Inf. Sci."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1016\/j.cose.2018.11.001","article-title":"Survey of machine learning techniques for malware analysis","volume":"81","author":"Ucci","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"102835","DOI":"10.1016\/j.cose.2022.102835","article-title":"On the relativity of time: Implications and challenges of data drift on long-term effective android malware detection","volume":"122","author":"Bahsi","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"100077","DOI":"10.1016\/j.array.2021.100077","article-title":"A survey on the application of deep learning for code injection detection","volume":"11","author":"Abaimov","year":"2021","journal-title":"Array"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"2023","DOI":"10.1016\/j.procs.2020.04.217","article-title":"A Comparative Study of Static Code Analysis tools for Vulnerability Detection in C\/C++ and JAVA Source Code","volume":"171","author":"Kaur","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1016\/j.future.2022.12.030","article-title":"A comparative study of adversarial training methods for neural models of source code","volume":"142","author":"Li","year":"2023","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_10","unstructured":"Caprile, B., Potrich, A., Ricca, F., and Tonella, P. (2003, January 22\u201326). Model centered interoperability for source code analysis. Proceedings of the STEP 2003, Workshop on Software Analysis and Maintenance: Practices, Tools, Interoperability, Amsterdam, The Netherlands."},{"key":"ref_11","unstructured":"Duffy, E. (2023, June 26). The Design & Implementation of an Abstract Semantic Graph for Statement-Level Dynamic Analysis of C++ Applications. Available online: https:\/\/tigerprints.clemson.edu\/cgi\/viewcontent.cgi?article=1832&context=all_dissertations."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"103121","DOI":"10.1016\/j.cose.2023.103121","article-title":"Insecurity Refactoring: Automated Injection of Vulnerabilities in Source Code","volume":"128","author":"Schuckert","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_13","unstructured":"(2023, June 26). Astdump 4.3. Available online: https:\/\/pypi.org\/project\/astdump\/."},{"key":"ref_14","unstructured":"Batchelder, N. (2023, June 26). The Structure of .pyc Files. Available online: https:\/\/nedbatchelder.com\/blog\/200804\/the_structure_of_pyc_files.html."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Patterson, E., Baldini, I., Mojsilovi\u0107, A., and Varshney, K.R. (2018, January 13\u201318). Semantic Representation of Data Science Programs. Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence, IJCAI-18, International Joint Conferences on Artificial Intelligence Organization, Stockholm, Sweden.","DOI":"10.24963\/ijcai.2018\/858"},{"key":"ref_16","unstructured":"Coet, A. (2023, June 26). StatiCFG. Available online: https:\/\/github.com\/coetaur0\/staticfg."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"102775","DOI":"10.1016\/j.cose.2022.102775","article-title":"Ap\u00edcula: Static detection of API calls in generic streams of bytes","volume":"119","author":"Salvadore","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_18","unstructured":"Blais, M. (2023, June 26). Snakefood: Python Dependency Graphs. Available online: https:\/\/github.com\/blais\/snakefood."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Yamaguchi, F., Golde, N., Arp, D., and Rieck, K. (2014, January 18\u201321). Modeling and Discovering Vulnerabilities with Code Property Graphs. Proceedings of the 2014 IEEE Symposium on Security and Privacy, Berkeley, CA, USA.","DOI":"10.1109\/SP.2014.44"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Gharibi, G., Tripathi, R., and Lee, Y. (2018, January 3\u20137). Code2graph: Automatic Generation of Static Call Graphs for Python Source Code. Proceedings of the 2018 33rd IEEE\/ACM International Conference on Automated Software Engineering (ASE), Montpellier, France.","DOI":"10.1145\/3238147.3240484"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"599","DOI":"10.1016\/j.neucom.2018.09.102","article-title":"Learning to detect Android malware via opcode sequences","volume":"396","author":"Acarman","year":"2020","journal-title":"Neurocomputing"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"101775","DOI":"10.1016\/j.cose.2020.101775","article-title":"Optimizing symbolic execution for malware behavior classification","volume":"93","author":"Sebastio","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"101688","DOI":"10.1016\/j.cose.2019.101688","article-title":"EspyDroid+: Precise reflection analysis of android apps","volume":"90","author":"Gajrani","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Narayanan, A., Soh, C., Chen, L., Liu, Y., and Wang, L. (2018, January 17\u201320). Apk2vec: Semi-Supervised Multi-view Representation Learning for Profiling Android Applications. Proceedings of the 2018 IEEE International Conference on Data Mining (ICDM), Singapore.","DOI":"10.1109\/ICDM.2018.00051"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"102459","DOI":"10.1016\/j.cose.2021.102459","article-title":"DouBiGRU-A: Software defect detection algorithm based on attention mechanism and double BiGRU","volume":"111","author":"Zhao","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Kalgutkar, V., Stakhanova, N., Cook, P., and Matyukhina, A. (2018, January 27\u201330). Android Authorship Attribution through String Analysis. Proceedings of the 13th International Conference on Availability, Reliability and Security, Hamburg, Germany.","DOI":"10.1145\/3230833.3230849"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"509","DOI":"10.1016\/j.future.2020.02.002","article-title":"Intelligent Mobile Malware Detection using Permission Requests and API calls","volume":"107","author":"Alazab","year":"2020","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"208","DOI":"10.1016\/j.cose.2019.02.007","article-title":"MalDAE: Detecting and explaining malware based on correlation and fusion of static and dynamic characteristics","volume":"83","author":"Han","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"102686","DOI":"10.1016\/j.cose.2022.102686","article-title":"A novel deep framework for dynamic malware detection based on API sequence intrinsic features","volume":"116","author":"Li","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"102154","DOI":"10.1016\/j.adhoc.2020.102154","article-title":"Malware detection in industrial internet of things based on hybrid image visualization and deep learning model","volume":"105","author":"Naeem","year":"2020","journal-title":"Ad Hoc Netw."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1016\/j.compeleceng.2019.03.015","article-title":"Identification of malicious code variants based on image visualization","volume":"76","author":"Naeem","year":"2019","journal-title":"Comput. Electr. Eng."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"102622","DOI":"10.1016\/j.cose.2022.102622","article-title":"EfficientNet convolutional neural networks-based Android malware detection","volume":"115","author":"Yadav","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"334","DOI":"10.1016\/j.future.2021.06.029","article-title":"MCFT-CNN: Malware classification with fine-tune convolution neural networks using traditional and transfer learning in Internet of Things","volume":"125","author":"Sudhakar","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"102660","DOI":"10.1016\/j.cose.2022.102660","article-title":"Image-based malware classification hybrid framework based on space-filling curves","volume":"116","author":"Sheridan","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., and Manjunath, B.S. (2011, January 20). Malware Images: Visualization and Automatic Classification. Proceedings of the 8th International Symposium on Visualization for Cyber Security, Pittsburgh, PA, USA.","DOI":"10.1145\/2016904.2016908"},{"key":"ref_36","unstructured":"Moses, T., and Barzanti, M. (2001). Static Analysis: A Dynamic Syntax Tree Implementation, BitBrainery University."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Neamtiu, I., Foster, J.S., and Hicks, M. (2005, January 15\u201316). Understanding Source Code Evolution Using Abstract Syntax Tree Matching. Proceedings of the 2005 International Workshop on Mining Software Repositories, New York, NY, USA.","DOI":"10.1145\/1083142.1083143"},{"key":"ref_38","unstructured":"D\u00e1niel, S., G\u00e1bor, S., \u00c1d\u00e1m, L., and Honfi, D. (2016). Graph-Based Source Code Analysis of Dynamically Typed Languages, Budapest University of Technology and Economics. Scientific Students\u2019 Association Report."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"739","DOI":"10.2478\/v10006-010-0056-9","article-title":"Control flow graphs and code coverage","volume":"20","author":"Gold","year":"2010","journal-title":"Int. J. Appl. Math. Comput. Sci."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"246","DOI":"10.1145\/93548.93576","article-title":"Dynamic program slicing","volume":"25","author":"Agrawal","year":"1990","journal-title":"ACM SIGPLAN Not."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1016\/0164-1212(92)90111-V","article-title":"Using program dependence graphs for information flow control","volume":"17","author":"Hsieh","year":"1992","journal-title":"J. Syst. Softw."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"102417","DOI":"10.1016\/j.cose.2021.102417","article-title":"VDSimilar: Vulnerability detection based on code similarity of vulnerabilities and patches","volume":"110","author":"Sun","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1016\/j.future.2020.10.020","article-title":"Pkg2Vec: Hierarchical package embedding for code authorship attribution","volume":"116","author":"Mateless","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"102591","DOI":"10.1016\/j.adhoc.2021.102591","article-title":"Generative adversarial network to detect unseen Internet of Things malware","volume":"122","author":"Moti","year":"2021","journal-title":"Ad Hoc Netw."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"102386","DOI":"10.1016\/j.cose.2021.102386","article-title":"Android malware detection via an app similarity graph","volume":"109","author":"Frenklach","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"111653","DOI":"10.1016\/j.jss.2023.111653","article-title":"Enhancing Ethereum smart-contracts static analysis by computing a precise Control-Flow Graph of Ethereum bytecode","volume":"200","author":"Pasqua","year":"2023","journal-title":"J. Syst. Softw."},{"key":"ref_47","first-page":"103267","article-title":"MaliCage: A packed malware family classification framework based on DNN and GAN","volume":"68","author":"Gao","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_48","first-page":"103467","article-title":"Detecting vulnerabilities in IoT software: New hybrid model and comprehensive data analysis","volume":"74","author":"Mei","year":"2023","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"103015","DOI":"10.1016\/j.cose.2022.103015","article-title":"MFXSS: An effective XSS vulnerability detection method in JavaScript based on multi-feature model","volume":"124","author":"Liu","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"106289","DOI":"10.1016\/j.infsof.2020.106289","article-title":"BVDetector: A program slice-based binary code vulnerability intelligent detection system","volume":"123","author":"Tian","year":"2020","journal-title":"Inf. Softw. Technol."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1016\/j.jss.2019.06.001","article-title":"Summarizing vulnerabilities\u2019 descriptions to support experts during vulnerability assessment activities","volume":"156","author":"Russo","year":"2019","journal-title":"J. Syst. Softw."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"103286","DOI":"10.1016\/j.cose.2023.103286","article-title":"Common vulnerability scoring system prediction based on open source intelligence information sources","volume":"131","author":"Relke","year":"2023","journal-title":"Comput. Secur."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/14\/9\/497\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T20:47:15Z","timestamp":1760129235000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/14\/9\/497"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,8]]},"references-count":52,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2023,9]]}},"alternative-id":["info14090497"],"URL":"https:\/\/doi.org\/10.3390\/info14090497","relation":{},"ISSN":["2078-2489"],"issn-type":[{"type":"electronic","value":"2078-2489"}],"subject":[],"published":{"date-parts":[[2023,9,8]]}}}