ProgSCA: Software Composition Analysis via Program-Level Modeling
Peihong Li, Cheng Li, Yuchen Gu, Yanzhe Hu, Liheng Chen, Zeyu Gao, Hao Wang, Chao Zhang
Abstract
Software composition analysis (SCA) aims to identify third-party dependencies in programs, which plays a critical role in ensuring software supply chain security. Existing approaches largely follow a rule-based paradigm: they first compute function-level similarities, then aggregate these results using handcrafted heuristics to determine which third-party libraries (TPLs) the target program depends on. However, such rules require substantial manual effort and expert knowledge to design, tune, and maintain. To address this, we present ProgSCA, an SCA framework based on a two-stage strategy and program-level rather than function-level modeling. ProgSCA formulates SCA as a retrieval problem, first employing lightweight methods to quickly filter out irrelevant libraries from numerous candidate TPLs, then using a model trained at the program level to directly predict dependency between programs. Comprehensive evaluations show that ProgSCA achieves state-of-the-art performance in SCA tasks, improving F1 scores over existing methods by 174% and 100% in two mainstream scenarios, respectively. Moreover, ProgSCA maintains a consistent advantage across different datasets and different candidate pool scales, and also proves effective in the downstream task of function similarity matching, further demonstrating the practical value of our approach.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4501b68a-d133-4b6c-bb01-e4168f1797beRelated papers
- VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability AnalysisYutao Hu, Chaofan Li, Yueming Wu, Yifeng Cai et al.NDSS 2026 · 1 citation
- DeepSCA: Dependency-Aware Software Composition Analysis for C/C++ Based on a Curated Code Feature DatabaseMeiqiu Xu, Xibin Zhao, Wenxuan Yu, Zhiliang Zhu et al.ISSTA 2026
- Beyond Similarity Scores: Evidence-Based Third-Party Library Detection for C/C++ BinariesChengyue Liu, Zhengzi Xu, Lyuye Zhang, Jiahui Wu et al.ISSTA 2026
- Understanding the Limitations of C/C++ Binary Third-Party Library Detection Tool: An Empirical Study at ScaleChengyue Liu, Zhengzi Xu, Kaixuan Li, Jiahui Wu et al.FSE 2026
- OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting FunctionsJiahui Wu, Zhengzi Xu, Wei Tang, Lyuye Zhang et al.ICSE 2023 · 29 citations
