USENIX Security2021Top-tier venue
V0Finder: Discovering the Correct Origin of Publicly Reported Software Vulnerabilities
Seunghoon Woo, Dongwook Lee, Sunghan Park, Heejo Lee, Sven Dietrich
Abstract
Common Vulnerabilities and Exposures (CVEs) are used to ensure confidence among developers, to share information about software vulnerabilities, and to provide a baseline for security measures. Therefore, the correctness of CVE reports is crucial for detecting and patching software vulnerabilities. In this paper, we introduce the concept of "Vulnerability Zero" (VZ), the software where a vulnerability first originated. We then present V0Finder, a precise mechanism for discovering the VZ of a vulnerability, including software name and its version. V0Finder utilizes code-based analysis to identify reuse relations, which specify the direction of vulnerability propagation, among vulnerable software. V0Finder constructs a graph from all the identified directions and traces backward to the root of that graph to find the VZ. We applied V0Finder to 5,671 CVE vulnerabilities collected from the National Vulnerability Database (NVD) and popular Bugzilla-based projects. V0Finder discovered VZs with high accuracy of 98% precision and 95% recall. Furthermore, V0Finder identified 96 CVEs with incorrect information related to their respective VZs. We confirmed that the incorrect VZ causes prolonged patch updates of vulnerable software; the patch update of CVEs with the incorrect VZ information takes 2 years, while the patch update of CVEs with the correct VZ takes less than a year on average. Such incorrectly identified VZ hinders the objective of the CVE and causes confusion rather than "ensuring confidence" among developers. Our analysis shows that V0Finder can enhance the credibility of information provided by the CVEs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 69bdd797-142d-41ce-8b70-796882c2949cCited by top-tier papers12
- FIRE: Combining Multi-Stage Filtering with Taint Analysis for Scalable Recurring Vulnerability DetectionSiyue Feng, Yueming Wu, Wenjie Xue, Sikui Pan et al.USENIX Security 2024 · 13 citations
- CNEPS: A Precise Approach for Examining Dependencies among Third-Party C/C++ Open-Source ComponentsYoonjong Na, Seunghoon Woo, Joomyeong Lee, Heejo LeeICSE 2024 · 11 citations
- SymBisect: Accurate Bisection for Fuzzer-Exposed VulnerabilitiesZheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou et al.USENIX Security 2024 · 7 citations
- Precise (Un)Affected Version Analysis for Web VulnerabilitiesYoukun Shi, Yuan Zhang, Tianhan Luo, Xiangyu Mao et al.ASE 2022 · 7 citations
- VMud: Detecting Recurring Vulnerabilities with Multiple Fixing Functions via Function Selection and Semantic Equivalent Statement MatchingKaifeng Huang, Chenhao Lu, Yiheng Cao, Bihuan Chen et al.CCS 2024 · 3 citations
Builds on8
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 388 citations
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- Towards the Detection of Inconsistencies in Public Security Vulnerability ReportsYing Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing et al.USENIX Security 2019 · 149 citations
- Understanding the Reproducibility of Crowd-reported Security VulnerabilitiesDongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu et al.USENIX Security 2018 · 138 citations
Related papers
- V-SZZ: Automatic Identification of Version Ranges Affected by CVE VulnerabilitiesLingfeng Bao, Xin Xia, Ahmed E. Hassan, Xiaohu YangICSE 2022 · 45 citations
- V1SCAN: Discovering 1-day Vulnerabilities in Reused C/C++ Open-source Software Components Using Code Classification TechniquesSeunghoon Woo, Eunjin Choi, Heejo Lee, Hakjoo OhUSENIX Security 2023
- Accurate Identification of the Vulnerability-Introducing Commit based on Differential Analysis of Patching PatternsQixuan Guo, Yongzhong HeNDSS 2026 · 1 citation
- PatchFinder: A Two-Phase Approach to Security Patch Tracing for Disclosed Vulnerabilities in Open-Source SoftwareKaixuan Li, Jian Zhang, Sen Chen, Han Liu et al.ISSTA 2024 · 8 citations
- Teaching AI the 'Why' and 'How' of Software Vulnerability FixesAmiao Gao, Zenong Zhang, Simin Wang, Liguo Huang et al.FSE 2025
