{"id":"W4400065514","doi":"10.1016/j.cose.2024.103971","title":"Detecting command injection vulnerabilities in Linux-based embedded firmware with LLM-based taint analysis of library functions","year":2024,"lang":"en","type":"article","venue":"Computers & Security","topic":"Security and Verification in Computing","field":"Computer Science","cited_by":15,"is_retracted":false,"has_abstract":false,"ca_institutions":"Carleton University","funders":"","keywords":"Firmware; Computer science; Taint checking; Operating system; Embedded system; Software","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0004468637,0.0005416509,0.0003516777,0.002167827,0.000239189,0.0005059391,0.0005867799,0.0004813223,0.0008288962],"category_scores_gemma":[0.003367037,0.0002186801,0.0004052515,0.0006762123,0.0004544437,0.001165726,0.0007084105,0.0004822134,0.0003290012],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0005113693,"about_ca_system_score_gemma":0.0006863945,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001603756,"about_ca_topic_score_gemma":0.003049355,"domain_scores_codex":[0.9991167,0.0001052833,0.0000590089,0.0001850103,0.0004015295,0.0001325828],"domain_scores_gemma":[0.9973091,0.0008431258,0.0008325715,0.0004416667,0.0004690469,0.0001045135],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"bench_or_experimental","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001478654,0.0007051103,0.2015585,0.0005590706,0.0002544347,0.001895885,0.001069671,0.02840283,0.4469391,0.003620751,0.003237975,0.310278],"study_design_scores_gemma":[0.00005262003,0.0006551736,0.08959427,0.00009256053,0.0001738545,0.001538568,0.0002962626,0.595579,0.306054,0.003466222,0.002395841,0.000101855],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.9208557,0.000408438,0.066278,0.0001116735,0.00003062791,0.00004532011,0.0002914032,0.01049597,0.001482861],"genre_scores_gemma":[0.9850726,0.00004768698,0.01414085,0.0000339302,0.000005454755,0.00001413307,0.0001479231,0.0001016993,0.0004358993],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.002167827,"threshold_uncertainty_score":0.00371021,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01266985832429048,"score_gpt":0.2408840868425788,"score_spread":0.2282142285182883,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}