On the vulnerability proneness of multilingual code
Wen Li, Li Li, Haipeng Cai
摘要
Software construction using multiple languages has long been a norm, yet it is still unclear if multilingual code construction has significant security implications and real security consequences. This paper aims to address this question with a large-scale study of popular multi-language projects on GitHub and their evolution histories, enabled by our novel techniques for multilingual code characterization. We found statistically significant associations between the proneness of multilingual code to vulnerabilities (in general and of specific categories) and its language selection. We also found this association is correlated with that of the language interfacing mechanism, not that of individual languages. We validated our statistical findings with in-depth case studies on actual vulnerabilities, explained via the mechanism and language selection. Our results call for immediate actions to assess and defend against multilingual vulnerabilities, for which we provide practical recommendations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- VGX: Large-Scale Sample Generation for Boosting Learning-Based Software Vulnerability AnalysesYu Nong, Richard Fang, Guangbei Yi, Kunsong Zhao 等ICSE 2024 · 被引用 23 次
- Generating realistic vulnerabilities via neural code editing: an empirical studyYu Nong, Yuzhe Ou, Michael Pradel, Feng Chen 等FSE 2022 · 被引用 23 次
- Demystifying Issues, Challenges, and Solutions for Multilingual Software DevelopmentHaoran Yang, Weile Lian, Shaowei Wang, Haipeng CaiICSE 2023 · 被引用 11 次
- Learning to Detect and Localize Multilingual BugsHaoran Yang, Yu Nong, Tao Zhang, Xiapu Luo 等FSE 2024 · 被引用 8 次
- Finding Compiler Bugs through Cross-Language Code Generator and Differential TestingQiong Feng, Xiaotian Ma, Ziyuan Feng, Marat Akhin 等OOPSLA 2025 · 被引用 2 次
它引用的顶会 Paper6
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen 等CCS 2018 · 被引用 93 次
- Broadening Horizons of Multilingual Static Analysis: Semantic Summary Extraction from C Code for JNI Program AnalysisSungho Lee, Hyogun Lee, Sukyoung RyuASE 2020 · 被引用 29 次
- FlowDist: Multi-Staged Refinement-Based Dynamic Information Flow Analysis for Distributed Software SystemsXiaoqin Fu, Haipeng CaiUSENIX Security 2021 · 被引用 26 次
- Generating realistic vulnerabilities via neural code editing: an empirical studyYu Nong, Yuzhe Ou, Michael Pradel, Feng Chen 等FSE 2022 · 被引用 23 次
- JUSTGen: Effective Test Generation for Unspecified JNI Behaviors on JVMsSungjae Hwang, Sungho Lee, Jihoon Kim, Sukyoung RyuICSE 2021 · 被引用 12 次
相关 Paper
- Insight: Exploring Cross-Ecosystem Vulnerability ImpactsMeiqiu Xu, Ying Wang, Shing-Chi Cheung, Hai Yu 等ASE 2022 · 被引用 12 次
- Dissecting Real-World Cross-Language BugsHaoran Yang, Haipeng CaiFSE 2025 · 被引用 2 次
- Diplomatist: What Do Cross-language Dependencies Reflect Software Ecosystem Health?Fanyi Meng, Ying Wang, Chun Yong Chong, Hai Yu 等ASE 2025
- PolyFuzz: Holistic Greybox Fuzzing of Multi-Language SystemsWen Li, Jinyang Ruan, Guangbei Yi, Long Cheng 等USENIX Security 2023
- “Write in English, Nobody Understands Your Language Here”: A Study of Non-English Trends in Open-Source RepositoriesMasudul Hasan Masud Bhuiyan, Manish Kumar Bala Kumar, Cristian-Alexandru StaicuICSE 2026 · 被引用 1 次
