CLEVER: Strengthening Cybersecurity with Timely Issue Mitigation and Recovery in Large-Scale Industrial Software Systems
Nandagopal Parise · 2025
In the realm of cybersecurity, the prevention and resolution of software faults are critical for safeguarding industrial systems against vulnerabilities. Existing approaches, such as metric-based models, have shown promise in identifying risky commits that could introduce defects. However, these models often suffer from high false positive rates and lack actionable guidance for developers to resolve detected issues. This paper introduces CLEVER (Combining Levels of Bug Prevention and Resolution techniques), a novel approach that enhances cybersecurity by intercepting risky commits before they reach central repositories. CLEVER integrates metric-based analysis with code-clone detection, enabling precise identification of risky commits and providing developers with recommendations for remediation. Tested on 12 large-scale systems from Ubisoft, CLEVER achieved 79% precision and 65% recall, outperforming prior tools like Commit-guru. Moreover, CLEVER successfully proposed qualitative fixes for risky commits in 66.7% of cases, demonstrating its practical applicability for reducing vulnerabilities and improving software resilience. This research highlights CLEVER’s potential as a cybersecurity-enhancing tool in industrial contexts, addressing the need for robust fault detection and resolution mechanisms.