Sign inSign up

miroslawstaron/ccsat

By miroslawstaron

•Updated over 2 years ago

cybersecurity analysis system

Image
0

258

miroslawstaron/ccsat repository overview

⁠Cybersecurity Software Analysis System

This container uses codeBERT and RoBERTa to check if source code has security vulnerabilities.

⁠Usage

Send a JSON string to the web service the /predict endpoint of this address. The JSON should contain three elements: code, model and vulnerability

⁠Models

Code is the code to be analyzed, and model is the name of the model to be used for the analysis. The model name should be one of the following:

  • codebert
  • singberta
⁠Vulnerabilities

At the moment, the tool can check for the following vulnerabilities:

  • sql_injection
  • input_validation
⁠Example JSON:
    {
        "code": "public class Test { public static void main(String[] args) { System.out.println(\"Hello World!\"); } }",
        "model": "codebert",
        "vulnerability": "input_validation"
    }

⁠Usage with CURL

This docker container exposes a web api at port 5001, so you need to map this port to a local one. It does not require access to local volumes. The endpoint for analysis is called prediction, e.g.: when we save the above JSON to a file test.json, we can use the following CURL:

curl -X POST -H "Content-Type: application/json" -d @tests/test.json http://localhost:5001/predict⁠

⁠Endpoints

  • / - shows a welcome message (GET)
  • /predict - makes the assessment of vulnerability (POST, see below)
  • /echo - send back what it receives, useful for debugging (GET) */vulnerabilities - shows the available vulnerabilities and models (GET)
  • /add_example - adds a new example and/or vulnerability (POST, see below)

⁠/add_example enpoint

 {
     "code": "...",
     "model": "singberta" or "codebert",
     "vulnerability": "input_validation",
     "type": "SCE" or "VCE"
  }

⁠/predict endpoint

    {
        "code": "public class Test { public static void main(String[] args) { System.out.println(\"Hello World!\"); } }",
        "model": "codebert",
        "vulnerability": "input_validation"
    }

⁠Contact

Metrics project: www.software-center.se⁠ and metrics.blogg.gu.se

Tag summary

Content type

Image

Digest

sha256:246e1a55b…

Size

9.6 GB

Last updated

over 2 years ago

docker pull miroslawstaron/ccsat