Skip to main content
Log in

VulLoc: vulnerability localization based on inducing commits and fixing commits

  • Letter
  • Published:
Frontiers of Computer Science Aims and scope Submit manuscript

Conclusion

In this paper, we explore the correlations between vul-inducing commits and vul-fixing commits, and propose an automated vulnerability localization approach called VulLoc to recommend a ranked list of suspicious methods. Compared with BugLocator, VulLoc can achieve an improvement on Einspect@n MAP, MRR, respectively and have significant efficiency on vulnerability localization.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Price excludes VAT (USA)
Tax calculation will be finalised during checkout.

Instant access to the full article PDF.

References

  1. Wen M, Wu R, Liu Y, Tian Y, Xie X, Cheung S C, Su Z. Exploring and exploiting the correlations between bug-inducing and bug-fixing commits. In: Proceedings of the 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering. 2019, 326–337

  2. Zou D, Liang J, Xiong Y, Ernst M D, Zhang L. An empirical study of fault localization families and their combinations. IEEE Transactions on Software Engineering, 2021, 47(2): 332–347

    Article  Google Scholar 

  3. Zhou J, Zhang H, Lo D. Where should the bugs be fixed? More accurate information retrieval-based bug localization based on bug reports. In: Proceedings of the 34th International Conference on Software Engineering. 2012, 14–24

Download references

Acknowledgements

This work was supported by the National Natural Science Foundation of China (Grant Nos. 61872312, 61972335, and 62002309); the Natural Science Foundation of the Jiangsu Higher Education Institutions of China (20KJB520016); the Innovation (Science and Technology) Project of Scientific Research Base of Nanjing University of Aeronautics and Astronautics (NJ2020022).

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Xiaobing Sun.

Electronic supplementary material

Rights and permissions

Reprints and permissions

About this article

Check for updates. Verify currency and authenticity via CrossMark

Cite this article

Bo, L., Li, Y., Sun, X. et al. VulLoc: vulnerability localization based on inducing commits and fixing commits. Front. Comput. Sci. 17, 173207 (2023). https://doi.org/10.1007/s11704-022-1729-x

Download citation

  • Received:

  • Accepted:

  • Published:

  • DOI: https://doi.org/10.1007/s11704-022-1729-x

Navigation