OpenSSF Finding and Fixing Vulnerabilities Using AI

1.1 Scope of this material

This is material on finding and fixing vulnerabilities in software using artificial intelligence (AI)/machine learning (ML). It is intended for:

It includes the process of finding, validating, and generating fixes, as well as related tasks that make this process more effective. These processes apply when examining the entire project or a particular set of proposed changes. We expect this material to apply to any software regardless of its license, but we do include a few notes specifically on open source software (OSS).

We don’t focus on any one specific system to do this. Many systems can help with this, more are being released, using multiple systems can be helpful, and the industry is rapidly changing. We instead focus on general principles that we believe are more timeless and will help you regardless of the systems you use to find and fix vulnerabilities. Once you understand the general issues, you’ll be more effective when using any particular system.

For a more general introduction on applying AI/ML to software development and security, see our course Secure AI/ML-Driven Software Development (LFEL1012) at https://training.linuxfoundation.org/express-learning/secure-ai-ml-driven-software-development-lfel1012/.

Please note that this material does NOT focus on the following topics:

  1. Building AI models & AI systems.
  2. Building/fixing software or systems that include AI. This material is still applicable, but we don’t discuss anything special related to that situation.
  3. How to write secure software in general. Please take our LFD121 course to learn that.
  4. Evaluating malicious or possibly-malicious software. We’re presuming that software developers are investigating their own software or software they want to contribute to, and that it isn’t intended to be malicious. The focus here is on unintentional vulnerabilities.

This material is a joint effort between the OpenSSF Best Practices working group (WG) and the OpenSSF AI/ML WG. Its lead author is David A. Wheeler. Reviewers include Laura Guazzelli.