AnchorDiff: Binary OSS Version Identification Method Based on Anchor Node Slicing
Zixuan Liang, Lei Zhou, Yongqiang Guo, Peihong Lin, Danjun Liu, Baosheng Wang, Xu Zhou
摘要
Binary Open-Source Software (OSS) is commonly embedded as third-party code within firmware and downstream software architectures, for simplifying the development process. However, vulnerabilities existing in OSS can be propagated through code reuse into embedded firmware and software architectures, posing security risks to these devices. To mitigate the security risks in firmware and software architectures, researchers have identified the versions of extracted firmware or binary software to detect N-day vulnerabilities in OSS. Existing works have achieved several success, but new challenges of non-linear update and minor updates hinder the improvement of the accuracy of binary OSS version identification.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- LibvDiff: Library Version Difference Guided OSS Version Identification in BinariesChaopeng Dong, Siyuan Li, Shouguo Yang, Yang Xiao 等ICSE 2024 · 被引用 9 次
- V1SCAN: Discovering 1-day Vulnerabilities in Reused C/C++ Open-source Software Components Using Code Classification TechniquesSeunghoon Woo, Eunjin Choi, Heejo Lee, Hakjoo OhUSENIX Security 2023
- Effective Vulnerable Function Identification based on CVE Description Empowered by Large Language ModelsYulun Wu, Ming Wen, Zeliang Yu, Xiaochen Guo 等ASE 2024 · 被引用 5 次
- Chronos: Large-Scale Online Firmware Version Detection via Inadvertent Chronological FingerprintsFengshi Zhang, Zhi Li, Shunchao Xu, Zekun Zhang 等INFOCOM 2026
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai 等USENIX Security 2024 · 被引用 33 次
