GitHub Implements Machine Learning System to Identify Vulnerabilities in Code

GitHub has announced the addition of an experimental machine learning system to the Code scanning service to identify common types of vulnerabilities in code. During the testing phase, this new functionality is currently available only for repositories with code in JavaScript and TypeScript. It is noted that the use of the machine learning system has significantly expanded the range of identified issues, as the analysis is no longer limited to checking template patterns and is not tied to known frameworks. Among the issues identified by the new system are errors leading to cross-site scripting (XSS), path traversal (e.g., through the specification of "\/.."), and injection of SQL and NoSQL queries.

The Code scanning service allows for the early detection of vulnerabilities during the development phase by scanning each 'git push' operation for potential issues. The results are directly attached to the pull request. Previously, checks were performed using the CodeQL engine, which analyzed patterns with typical examples of vulnerable code (CodeQL allows the creation of a vulnerable code pattern to detect similar vulnerabilities in the code of other projects). The new engine, which uses machine learning, can identify previously unknown vulnerabilities as it is not tied to enumerating code patterns that describe specific vulnerabilities. The price of this capability is an increase in false positives compared to checks based on CodeQL.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster