Identifying Open-Source License Violation and 1-day Security Risk at Large Scale
Ruian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim, Wenke Lee
摘要
With millions of apps available to users, the mobile app market is rapidly becoming very crowded. Given the intense competition, the time to market is a critical factor for the success and profitability of an app. In order to shorten the development cycle, developers often focus their efforts on the unique features and workflows of their apps and rely on third-party Open Source Software (OSS) for the common features. Unfortunately, despite their benefits, careless use of OSS can introduce significant legal and security risks, which if ignored can not only jeopardize security and privacy of end users, but can also cause app developers high financial loss. However, tracking OSS components, their versions, and interdependencies can be very tedious and error-prone, particularly if an OSS is imported with little to no knowledge of its provenance. We therefore propose OSSPolice, a scalable and fully-automated tool for mobile app developers to quickly analyze their apps and identify free software license violations as well as usage of known vulnerable versions of OSS. OSSPolice introduces a novel hierarchical indexing scheme to achieve both high scalability and accuracy, and is capable of efficiently comparing similarities of app binaries against a database of hundreds of thousands of OSS sources (billions of lines of code). We populated OSSPolice with 60K C/C++ and 77K Java OSS sources and analyzed 1.6M free Google Play Store apps. Our results show that 1) over 40K apps potentially violate GPL/AGPL licensing terms, and 2) over 100K of apps use known vulnerable versions of OSS. Further analysis shows that developers violate GPL/AGPL licensing terms due to lack of alternatives, and use vulnerable versions of OSS despite efforts from companies like Google to improve app security. OSSPolice is available on GitHub.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper43
- CodeCMR: Cross-Modal Retrieval For Function-Level Binary Source Code MatchingZeping Yu, Wenxin Zheng, Jiaqi Wang, Qiyi Tang 等NeurIPS 2020 · 被引用 93 次
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu 等ICSE 2021 · 被引用 85 次
- CyberGym: Evaluating AI Agents' Real-World Cybersecurity Capabilities at ScaleZhun Wang, Tianneng Shi, Jingxuan He, Matthew Cai 等ICLR 2026 · 被引用 83 次
- Patch based vulnerability matching for binary programsYifei Xu, Zhengzi Xu, Bihuan Chen, Fu Song 等ISSTA 2020 · 被引用 74 次
- Towards Understanding Third-party Library Dependency in C/C++ EcosystemWei Tang, Zhengzi Xu, Chengwei Liu, Jiahui Wu 等ASE 2022 · 被引用 64 次
它引用的顶会 Paper4
- Scalable Graph-based Bug Search for Firmware ImagesQian Feng, Rundong Zhou, Chengcheng Xu, Yao Cheng 等CCS 2016 · 被引用 456 次
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 被引用 388 次
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 被引用 345 次
- discovRE: Efficient Cross-Architecture Identification of Bugs in Binary CodeSebastian Eschweiler, Khaled Yakdan, Elmar Gerhards-PadillaNDSS 2016 · 被引用 342 次
相关 Paper
- OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting FunctionsJiahui Wu, Zhengzi Xu, Wei Tang, Lyuye Zhang 等ICSE 2023 · 被引用 29 次
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky 等S&P 2017 · 被引用 293 次
- Automating Patching of Vulnerable Open-Source Software Versions in Application BinariesRuian Duan, Ashish Bijlani, Yang Ji, Omar Alrawi 等NDSS 2019 · 被引用 63 次
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar 等CCS 2017 · 被引用 196 次
- LibScan: Towards More Precise Third-Party Library Identification for Android ApplicationsYafei Wu, Cong Sun, Dongrui Zeng, Gang Tan 等USENIX Security 2023
