遇见数据集

Software Assurance Reference Dataset

收藏
DataCite Commons2020-07-30 更新2025-04-09 收录
官方服务:

资源简介:

The programs are in C, C++, Java, PHP, and C# and cover more than 150 classes of weaknesses, such as SQL injection, cross-site scripting (XSS), buffer overflow, and use of a broken cryptographic algorithm. Most are automatically generated synthetic programs, each a few pages of code long, but there are also over 7000 full-sized applications. In addition, SARD has production code and has hundreds of cases written by hand. The code is typical quality. It is neither pristine nor obfuscated. Many cases have corresponding “good” cases, in which weaknesses are fixed, to test for false positives. The SARD web interface allows users to browse test cases and test suites or search for test cases by programming language, weakness type, file name, size, words in the description, and several other criteria. The user can select and download any or all of the resulting cases. Each test case has metadata to describe it. Most bugs or weaknesses are recorded in metadata. Weaknesses are classified using the Common Weakness Enumeration (CWE) ID and name. We plan to add their Bugs Framework (BF) class and attributes.

本数据集涵盖C、C++、Java、PHP及C#语言编写的程序,包含超过150类安全弱点,例如SQL注入、跨站脚本(XSS)、缓冲区溢出以及使用存在缺陷的加密算法等。其中绝大多数为自动生成的合成程序,单份代码长度约为数页,同时还包含超过7000个完整规模的应用程序。此外,SARD还包含生产级代码,以及数百份手工编写的测试用例。这些代码的质量处于常规水准,既非完全纯净无瑕疵的初始版本,也未经过代码混淆处理。多数测试用例均配有对应的‘修复后用例’——即已消除对应安全弱点的版本——以用于检测假阳性结果。SARD的网页界面支持用户浏览测试用例与测试套件,也可根据编程语言、弱点类型、文件名、文件大小、描述文本中的关键词及其他多项标准检索测试用例。用户可选择并下载任意或全部符合检索条件的测试用例。每份测试用例均配有描述性元数据,绝大多数漏洞与安全弱点的相关信息均存储于元数据中。安全弱点均采用通用弱点枚举(Common Weakness Enumeration)的编号与名称进行分类。我们计划后续添加其缺陷框架(Bugs Framework)的分类与属性信息。

提供机构:
IMPACT
创建时间:
2019-09-10
搜集汇总
数据集介绍
Software Assurance Reference Dataset 数据集图片
背景与挑战
背景概述
Software Assurance Reference Dataset(SARD)是一个外部数据集,由国家标准与技术研究院托管,包含超过170,000个用多种编程语言编写的程序,精确标注了错误位置。它覆盖150多个弱点类别,如SQL注入和缓冲区溢出,并提供元数据和Web界面以支持软件安全测试和研究。
以上内容由遇见数据集搜集并总结生成
二维码
社区交流群
二维码
科研交流群
商业服务