[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118147-en":3,"doc-seo-118147-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":11,"language":21,"language_code":22,"site_id":23,"html_lang":22,"table_of_contents":24,"faqs":25,"seo_title":26,"seo_description":14,"update_tm":27,"read_time":28},118147,2336464648322,"Aria","https://ap-avatar.wpscdn.com/avatar/2200025388227c56fec?_k=1778556882303663488",6,"Technology","Detecting Security-Relevant Methods using Multi-label Machine Learning","Static analysis tools require security-relevant methods to be configured correctly to detect software vulnerabilities, yet existing machine-learning approaches based on binary relevance often ignore dependencies among security-relevant method types, over-generalize, and underperform in practice. They also shift substantial work back to users, who still need to manually configure SAST tools with the detected methods. Dev-Assist, an IntelliJ IDEA plugin, uses multi-label learning to model label dependencies, automatically generates static-analysis configurations, runs SAST, and presents results inside the IDE. Experiments show improved F1-measure and reduced manual effort.","Detecting Security-Relevant Methods using Multi-label Machine  \nLearning  \nOshando Johnson  \n[oshando.johnson@iem.fraunhofer.de](oshando.johnson@iem.fraunhofer.de)[ ](oshando.johnson@iem.fraunhofer.de)Fraunhofer IEM Paderborn, Germany  \nGoran Piskachev  \n[gpiskach@amazon.de](gpiskach@amazon.de)[ ](gpiskach@amazon.de)Amazon Web Services Berlin, Germany  \narXiv :2403 .07501v1 [ cs .LG] 12 Mar 2024  \nRanjith Krishnamurthy  \n[ranjith.krishnamurthy@iem.fraunhofer.de](ranjith.krishnamurthy@iem.fraunhofer.de)[ ](ranjith.krishnamurthy@iem.fraunhofer.de)Fraunhofer IEM Paderborn, Germany  \nEric Bodden  \neric.bodden@uni-paderborn.de Paderborn University and Fraunhofer IEM Paderborn, Germany  \nABSTRACT  \nTo detect security vulnerabilities, static analysis tools need to be configured with security-relevant methods. Current approaches can automatically identify such methods using binary relevance machine learning approaches. However, they ignore dependencies among security-relevant methods, over-generalize and perform poorly in practice. Additionally, users have to nevertheless manually configure static analysis tools using the detected methods. Based on feedback from users and our observations, the excessive manual steps can often be tedious, error-prone and counter-intuitive.  \nIn this paper, we present Dev-Assist, an IntelliJ IDEA plugin that detects security-relevant methods using a multi-label machine learning approach that considers dependencies among labels. The plugin can automatically generate configurations for static analysis tools, run the static analysis, and show the results in IntelliJ IDEA. Our experiments reveal that Dev-Assist’s machine learning approach has a higher F1-Measure than related approaches. Moreover, the plugin reduces and simplifies the manual effort required when configuring and using static analysis tools.  \nCCS CONCEPTS  \n• Security and privacy → Software security engineering; Software security engineering; Systems security; Vulnerability scanners; • Software and its engineering → Software verification and validation.  \nKEYWORDS  \nStatic Analysis, Software Security, Machine Learning, Vulnerability Detection, Multi-label learning, IntelliJ Plugin development  \nACM Reference Format:  \nOshando Johnson, Goran Piskachev, Ranjith Krishnamurthy, and Eric Bodden. 2024. Detecting Security-Relevant Methods using Multi-label Machine Learning. In 2024 First IDE Workshop (IDE ’24), April 20, 2024, Lisbon, Portugal. ACM, New York, NY, USA, 6 pages. [https://doi.org/10.1145/3643796.3648464](https://doi.org/10.1145/3643796.3648464)  \nPermission to make digital or hard copies of part or all ofthis work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the owner/author(s) .  \nIDE ’24, April 20, 2024, Lisbon, Portugal  \n© 2024 Copyright held by the owner/author(s) .  \nACM ISBN 979-8-4007-0580-9/24/04 .  \n[https://doi.org/10.1145/3643796.3648464](https://doi.org/10.1145/3643796.3648464)  \n1 INTRODUCTION  \nWith the continued rise in the number of reported software vulnerabilities [6] such as those in the 2023 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses list [5], more and more companies resort to Static Application Security Testing (SAST) tools to detect vulnerabilities. Yet, to be able to detect security vulnerabilities effectively, experts currently need to correctly configure and adapt the SAST tools. One required configuration comprises security-relevant methods (SRM), which are critical points in a program that have an impact on the analysis [19] . SRMs relevant for detecting taint-style vulnerabilities include sources (methods that create data that the analysis should track), sinks (methods at which the analysis might need to raise an alar","cbCaimvVA0csNXWS","https://ap.wps.com/l/cbCaimvVA0csNXWS","pdf",1313700,1,"English","en",105,"# Abstract\n# Introduction\n## Security-relevant methods in SAST\n## Multi-label learning for SRM detection","[{\"question\":\"Why do current binary-relevance ML approaches underperform for security-relevant method detection?\",\"answer\":\"They ignore dependencies among security-relevant methods and tend to over-generalize, which leads to weaker practical performance.\"},{\"question\":\"What is Dev-Assist and what problem does it address?\",\"answer\":\"Dev-Assist is an IntelliJ IDEA plugin that detects security-relevant methods using multi-label learning with dependencies, reducing tedious and error-prone manual configuration steps.\"},{\"question\":\"How does Dev-Assist help users beyond detecting security-relevant methods?\",\"answer\":\"It can automatically generate configurations for static analysis tools, execute the analysis, and display results directly in IntelliJ IDEA.\"}]","Detecting Security-Relevant Methods using Multi-label Machine Learning | PDF",1785681889,15,{"code":4,"msg":30,"data":31},"ok",{"site_id":23,"language":22,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"detecting-security-relevant-methods-using-multi-label-machine-learning","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/technology/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/detecting-security-relevant-methods-using-multi-label-machine-learning/118147/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":22,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"Why do current binary-relevance ML approaches underperform for security-relevant method detection?","Question",{"text":74,"@type":75},"They ignore dependencies among security-relevant methods and tend to over-generalize, which leads to weaker practical performance.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"What is Dev-Assist and what problem does it address?",{"text":79,"@type":75},"Dev-Assist is an IntelliJ IDEA plugin that detects security-relevant methods using multi-label learning with dependencies, reducing tedious and error-prone manual configuration steps.",{"name":81,"@type":72,"acceptedAnswer":82},"How does Dev-Assist help users beyond detecting security-relevant methods?",{"text":83,"@type":75},"It can automatically generate configurations for static analysis tools, execute the analysis, and display results directly in IntelliJ IDEA.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":23},{"code":4,"msg":5,"data":91},[92,96,100,104,109,112,117,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":110,"slug":111},50,"technology",{"id":113,"doc_module":4,"doc_module_name":45,"category_name":114,"show_sort_weight":115,"slug":116},7,"Healthcare",40,"healthcare",{"id":118,"doc_module":4,"doc_module_name":45,"category_name":119,"show_sort_weight":120,"slug":121},8,"Research & Report",30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":105,"slug":137},19,"General","general"]