ProgSCA: Software Composition Analysis via Program-Level Modeling
Peihong Li, Cheng Li, Yuchen Gu, Yanzhe Hu, Liheng Chen, Zeyu Gao, Hao Wang, Chao Zhang
摘要
Software composition analysis (SCA) aims to identify third-party dependencies in programs, which plays a critical role in ensuring software supply chain security. Existing approaches largely follow a rule-based paradigm: they first compute function-level similarities, then aggregate these results using handcrafted heuristics to determine which third-party libraries (TPLs) the target program depends on. However, such rules require substantial manual effort and expert knowledge to design, tune, and maintain. To address this, we present ProgSCA, an SCA framework based on a two-stage strategy and program-level rather than function-level modeling. ProgSCA formulates SCA as a retrieval problem, first employing lightweight methods to quickly filter out irrelevant libraries from numerous candidate TPLs, then using a model trained at the program level to directly predict dependency between programs. Comprehensive evaluations show that ProgSCA achieves state-of-the-art performance in SCA tasks, improving F1 scores over existing methods by 174% and 100% in two mainstream scenarios, respectively. Moreover, ProgSCA maintains a consistent advantage across different datasets and different candidate pool scales, and also proves effective in the downstream task of function similarity matching, further demonstrating the practical value of our approach.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability AnalysisYutao Hu, Chaofan Li, Yueming Wu, Yifeng Cai 等NDSS 2026 · 被引用 1 次
- DeepSCA: Dependency-Aware Software Composition Analysis for C/C++ Based on a Curated Code Feature DatabaseMeiqiu Xu, Xibin Zhao, Wenxuan Yu, Zhiliang Zhu 等ISSTA 2026
- Beyond Similarity Scores: Evidence-Based Third-Party Library Detection for C/C++ BinariesChengyue Liu, Zhengzi Xu, Lyuye Zhang, Jiahui Wu 等ISSTA 2026
- Understanding the Limitations of C/C++ Binary Third-Party Library Detection Tool: An Empirical Study at ScaleChengyue Liu, Zhengzi Xu, Kaixuan Li, Jiahui Wu 等FSE 2026
- OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting FunctionsJiahui Wu, Zhengzi Xu, Wei Tang, Lyuye Zhang 等ICSE 2023 · 被引用 29 次
