Method and System for Reducing False Positives in Static Source Code Analysis Reports Using Machine Learning and Classification Techniques
Patent №
US 11,620,389
Granted
2023-04-04
Filed 2020
Owner
UNIVERSITY OF MARYLAND BALTIMORE COUNTY
Lab
—
AI components
5
ml · nlp · kr · planning · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
16911373
This invention is a computer-implemented method and system of using a secondary classification algorithm after using a primary source code vulnerability scanning tool to more accurately label true and false vulnerabilities in source code. The method and system use machine learning within a 10% dataset to develop a classifier model algorithm. A selection process identifies the most important features utilized in the algorithm to detect and distinguish the true and false positive findings of the static code analysis results. A personal identifier is used as a critical feature for the classification. The model is validated by experimentation and comparison against thirteen existing classifiers.
AI classification
Ownership
UNIVERSITY OF MARYLAND BALTIMORE COUNTY
assignment · 532460517