VUDDY: A Scalable Approach for Vulnerable Code Clone Discovery
Seulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo Oh
Abstract
The ecosystem of open source software (OSS) has been growing considerably in size. In addition, code clones -code fragments that are copied and pasted within or between software systems -are also proliferating. Although code cloning may expedite the process of software development, it often critically affects the security of software because vulnerabilities and bugs can easily be propagated through code clones. These vulnerable code clones are increasing in conjunction with the growth of OSS, potentially contaminating many systems. Although researchers have attempted to detect code clones for decades, most of these attempts fail to scale to the size of the ever-growing OSS code base. The lack of scalability prevents software developers from readily managing code clones and associated vulnerabilities. Moreover, most existing clone detection techniques focus overly on merely detecting clones and this impairs their ability to accurately find "vulnerable" clones. In this paper, we propose VUDDY, an approach for the scalable detection of vulnerable code clones, which is capable of detecting security vulnerabilities in large software programs efficiently and accurately. Its extreme scalability is achieved by leveraging function-level granularity and a length-filtering technique that reduces the number of signature comparisons. This efficient design enables VUDDY to preprocess a billion lines of code in 14 hour and 17 minutes, after which it requires a few seconds to identify code clones. In addition, we designed a security-aware abstraction technique that renders VUDDY resilient to common modifications in cloned code, while preserving the vulnerable conditions even after the abstraction is applied. This extends the scope of VUDDY to identifying variants of known vulnerabilities, with high accuracy. In this study, we describe its principles and evaluate its efficacy and effectiveness by comparing it with existing mechanisms and presenting the vulnerabilities it detected. VUDDY outperformed four state-of-the-art code clone detection techniques in terms of both scalability and accuracy, and proved its effectiveness by detecting zero-day vulnerabilities in widely used software systems, such as Apache HTTPD and Ubuntu OS Distribution.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9af9fe7c-8dd4-41c2-b374-3b7a3ea19768Cited by top-tier papers65
- VulCNN: An Image-inspired Scalable Vulnerability Detection SystemYueming Wu, Deqing Zou, Shihan Dou, Wei Yang et al.ICSE 2022 · 141 citations
- Identifying Open-Source License Violation and 1-day Security Risk at Large ScaleRuian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim et al.CCS 2017 · 126 citations
- Precise and Accurate Patch Presence Test for BinariesHang Zhang, Zhiyun QianUSENIX Security 2018 · 91 citations
- Patch based vulnerability matching for binary programsYifei Xu, Zhengzi Xu, Bihuan Chen, Fu Song et al.ISSTA 2020 · 74 citations
- Automating Patching of Vulnerable Open-Source Software Versions in Application BinariesRuian Duan, Ashish Bijlani, Yang Ji, Omar Alrawi et al.NDSS 2019 · 63 citations
Related papers
- MOVERY: A Precise Approach for Modified Vulnerable Code Clone Discovery from Modified Open-Source Software ComponentsSeunghoon Woo, Hyunji Hong, Eunjin Choi, Heejo LeeUSENIX Security 2022
- FIRE: Combining Multi-Stage Filtering with Taint Analysis for Scalable Recurring Vulnerability DetectionSiyue Feng, Yueming Wu, Wenjie Xue, Sikui Pan et al.USENIX Security 2024 · 13 citations
- Similar but Patched Code Considered Harmful: The Impact of Similar but Patched Code on Recurring Vulnerability Detection and How to Remove ThemZixuan Tan, Jiayuan Zhou, Xing Hu, Shengyi Pan et al.ICSE 2025 · 1 citation
- VMud: Detecting Recurring Vulnerabilities with Multiple Fixing Functions via Function Selection and Semantic Equivalent Statement MatchingKaifeng Huang, Chenhao Lu, Yiheng Cao, Bihuan Chen et al.CCS 2024 · 3 citations
- Centris: A Precise and Scalable Approach for Identifying Modified Open-Source Software ReuseSeunghoon Woo, Sunghan Park, Seulbae Kim, Heejo Lee et al.ICSE 2021 · 2 citations
