LibAlchemy: A Two-Layer Persistent Summary Design for Taming Third-Party Libraries in Static Bug-Finding Systems
Rongxin Wu, Yuxuan He, Jiafeng Huang, Chengpeng Wang, Wensheng Tang, Qingkai Shi, Xiao Xiao, Charles Zhang
摘要
Despite the benefits of using third-party libraries (TPLs), the misuse of TPL functions raises quality and security concerns. Using traditional static analysis to detect bugs caused by TPL function is non-trivial. One promising solution would be to automatically generate and persist the summaries of TPL functions offline and then reuse these summaries in compositional static analysis online. However, when dealing with millions of lines of TPL code, the summaries designed by existing studies suffer from an unresolved paradox. That is, a highly precise form of summary leads to an unaffordable space and time overhead, while an imprecise one seriously hurts its precision or recall.
To address the paradox, we propose a novel two-layer summary design. The first layer utilizes a line-sized program representation known as the program dependence graph to compactly encode path conditions, while the second layer encodes bug-type-specific properties. We implemented our idea as a tool called LibAlchemy and evaluated it on fifteen mature and extensively checked opensource projects. Experimental results show that LibAlchemy can check over ten million lines of code within ten hours. LibAlchemy has detected 55 true bugs with a high precision of 90.16%, eleven of which have been assigned CVE IDs. Compared to whole-program
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Preserving Privacy in Software Composition Analysis: A Study of Technical Solutions and EnhancementsHuaijin Wang, Zhibo Liu, Yanbo Dai, Shuai Wang 等ICSE 2025 · 被引用 2 次
- Boosting Path-Sensitive Value Flow Analysis Via Removal of Redundant SummariesYongchao Wang, Yuandao Cai, Charles ZhangICSE 2025 · 被引用 1 次
- ProSec: Fortifying Code LLMs with Proactive Security AlignmentXiangzhe Xu, Zian Su, Jinyao Guo, Kaiyuan Zhang 等ICML 2025
它引用的顶会 Paper10
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 被引用 388 次
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu 等ICSE 2021 · 被引用 85 次
- Extracting taint specifications for JavaScript librariesCristian-Alexandru Staicu, Martin Toldam Torp, Max Schäfer, Anders Møller 等ICSE 2020 · 被引用 34 次
- Path-sensitive sparse analysis without path conditionsQingkai Shi, Peisen Yao, Rongxin Wu, Charles ZhangPLDI 2021 · 被引用 24 次
- Chianina: an evolving graph system for flow- and context-sensitive analyses of million lines of C codeZhiqiang Zuo, Yiyu Zhang, Qiuhong Pan, Shenming Lu 等PLDI 2021 · 被引用 18 次
相关 Paper
- OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting FunctionsJiahui Wu, Zhengzi Xu, Wei Tang, Lyuye Zhang 等ICSE 2023 · 被引用 29 次
- Understanding the Limitations of C/C++ Binary Third-Party Library Detection Tool: An Empirical Study at ScaleChengyue Liu, Zhengzi Xu, Kaixuan Li, Jiahui Wu 等FSE 2026
- An Empirical Study on the Robustness of Android Third-Party Library Detection Tools Against Advanced ObfuscationDahan Pan, Zhuohao Zhang, Yunjia Min, Runhan Feng 等ICSE 2026
- LibScan: Towards More Precise Third-Party Library Identification for Android ApplicationsYafei Wu, Cong Sun, Dongrui Zeng, Gang Tan 等USENIX Security 2023
- Enhancing Security in Third-Party Library Reuse - Comprehensive Detection of 1-day Vulnerability through Code Patch AnalysisShangzhi Xu, Jialiang Dong, Weiting Cai, Juanru Li 等NDSS 2025
