Strengthening Supply Chain Security with Fine-grained Safe Patch Identification
Changhua Luo, Wei Meng, Shuai Wang
Abstract
Enhancing supply chain security is crucial, often involving the detection of patches in upstream software. However, current security patch analysis works yield relatively low recall rates (i.e., many security patches are missed). In this work, we offer a new solution to detect safe patches and assist downstream developers in patch propagation. Specifically, we develop SPatch to detect fine-grained safe patches. SPatch leverages fine-grained patch analysis and a new differential symbolic execution technique to analyze the functional impacts of code changes. We evaluated SPatch on various software, including the Linux kernel and OpenSSL, and demonstrated that it outperformed existing methods in detecting safe patches, resulting in observable security benefits. In our case studies, we updated hundreds of functions in modern software using safe patches detected by SPatch without causing any regression issues. Our detected safe security patches have been merged into the latest version of downstream software like ProtonVPN. CCS CONCEPTS • Security and privacy → Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3d1be962-4417-47a6-867e-5d793f2de072Cited by top-tier papers2
- Vulnerability-Affected Versions Identification: How Far Are We?Xingchu Chen, Chengwei Liu, Jialun Cao, Yang Xiao et al.ASE 2025 · 3 citations
- DISPATCH: Unraveling Security Patches from Entangled Code ChangesShiyu Sun, Yunlong Xing, Xinda Wang, Shu Wang et al.USENIX Security 2025
Builds on16
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 388 citations
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 142 citations
- Using Safety Properties to Generate Vulnerability PatchesZhen Huang, David Lie, Gang Tan, Trent JaegerS&P 2019 · 91 citations
- An Investigation of the Android Kernel Patch EcosystemZheng Zhang, Hang Zhang, Zhiyun Qian, Billy LauUSENIX Security 2021 · 45 citations
- ARDiff: scaling program equivalence checking via iterative abstraction and refinement of common codeSahar Badihi, Faridah Akinotcho, Yi Li, Julia RubinFSE 2020 · 44 citations
Related papers
- What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory BugsXingyu Li, Juefei Pu, Yifan Wu, Xiaochen Zou et al.NDSS 2026 · 2 citations
- SPIDER: Enabling Fast Patch Propagation In Related Software RepositoriesAravind Machiry, Nilo Redini, Eric Camellini, Christopher Kruegel et al.S&P 2020 · 39 citations
- RTrace: Towards Better Visibility of Shared Library ExecutionHuaifeng Zhang, Ahmed Ali-EldinNDSS 2026
- VeriBin: Adaptive Verification of Patches at the Binary LevelHongwei Wu, Jianliang Wu, Ruoyu Wu, Ayushi Sharma et al.NDSS 2025
- Decades of GNU Patch and Git Cherry-Pick: Can We Do Better?Alexander Schultheiß, Alexander Boll, Paul Maximilian Bittner, Sandra Greiner et al.ICSE 2026
