Beyond Similarity Scores: Evidence-Based Third-Party Library Detection for C/C++ Binaries
Chengyue Liu, Zhengzi Xu, Lyuye Zhang, Jiahui Wu, Kaixuan Li, Yang Liu
摘要
Detecting third-party libraries (TPLs) in C/C++ binaries is essential for software supply chain security, enabling vulnerability identification and license compliance. Existing methods predominantly rely on similarity matching: extracting features from binaries and comparing them against library databases. However, similarity scores alone cannot reliably determine library presence. Low similarity causes false negatives when matchable features are limited. More critically, high similarity does not guarantee accuracy: libraries often share features through shared dependencies, forks, or similar functionality, causing multiple candidates to match even when only one is present. These issues suggest that similarity matching is effective for narrowing candidates but insufficient as the final decision mechanism. Rather than relying solely on similarity scores, reliable detection requires multi-source evidence to verify each candidate. To this end, we propose BLADE, which reframes TPL detection as evidence-based candidate verification. Instead of relying on similarity scores to make final decisions, BLADE retrieves candidates broadly to mitigate false negatives, and then collects evidence from multiple sources, which an LLM analyzes through structured verification workflows to filter false positives: first confirming candidates with clear identity markers, then systematically checking remaining candidates against common false positive patterns. To evaluate BLADE, we build the largest C/C++ binary TPL benchmark to date, comprising 3,403 binaries and 1,016 libraries. Results show that BLADE achieves 97.60% precision and 93.74% recall (F1: 95.63%), improving F1-score by 41.83 percentage points over the best baseline. The average cost is $0.0378 per binary. BLADE has been deployed in a commercial software composition analysis product, demonstrating practical feasibility at scale.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Understanding the Limitations of C/C++ Binary Third-Party Library Detection Tool: An Empirical Study at ScaleChengyue Liu, Zhengzi Xu, Kaixuan Li, Jiahui Wu 等FSE 2026
- VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability AnalysisYutao Hu, Chaofan Li, Yueming Wu, Yifeng Cai 等NDSS 2026 · 被引用 1 次
- DeepSCA: Dependency-Aware Software Composition Analysis for C/C++ Based on a Curated Code Feature DatabaseMeiqiu Xu, Xibin Zhao, Wenxuan Yu, Zhiliang Zhu 等ISSTA 2026
- OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting FunctionsJiahui Wu, Zhengzi Xu, Wei Tang, Lyuye Zhang 等ICSE 2023 · 被引用 29 次
- ProgSCA: Software Composition Analysis via Program-Level ModelingPeihong Li, Cheng Li, Yuchen Gu, Yanzhe Hu 等ISSTA 2026
