Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java Projects
Lida Zhao, Sen Chen, Zhengzi Xu, Chengwei Liu, Lyuye Zhang, Jiahui Wu, Jun Sun, Yang Liu
摘要
Software composition analysis (SCA) tools are proposed to detect potential vulnerabilities introduced by open-source software (OSS) imported as third-party libraries (TPL). With the increasing complexity of software functionality, SCA tools may encounter various scenarios during the dependency resolution process, such as diverse formats of artifacts, diverse dependency imports, and diverse dependency specifications. However, there still lacks a comprehensive evaluation of SCA tools for Java that takes into account the above scenarios. This could lead to a confined interpretation of comparisons, improper use of tools, and hinder further improvements of the tools. To fill this gap, we proposed an Evaluation Model which consists of Scan Modes, Scan Methods, and SCA Scope for Maven (SSM), for comprehensive assessments of the dependency resolving capabilities and effectiveness of SCA tools. Based on the Evaluation Model, we first qualitatively examined 6 SCA tools’ capabilities. Next, the accuracy of dependency and vulnerability is quantitatively evaluated with a large-scale dataset (21,130 Maven modules with 73,499 unique dependencies) under two Scan Modes (i.e., build scan and pre-build scan). The results show that most tools do not fully support SSM, which leads to compromised accuracy. For dependency detection, the average F1-score is 0.890 and 0.692 for build and pre-build respectively, and for vulnerability accuracy, the average F1-score is 0.475. However, proper support for SSM reduces dependency detection false positives by 34.24% and false negatives by 6.91%. This further leads to a reduction of 18.28% in false positives and 8.72% in false negatives in vulnerability reports.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper12
- Mitigating Persistence of Open-Source Vulnerabilities in Maven EcosystemLyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu 等ASE 2023 · 被引用 25 次
- Empirical Analysis of Vulnerabilities Life Cycle in Golang EcosystemJinchang Hu, Lyuye Zhang, Chengwei Liu, Sen Yang 等ICSE 2024 · 被引用 10 次
- PatchFinder: A Two-Phase Approach to Security Patch Tracing for Disclosed Vulnerabilities in Open-Source SoftwareKaixuan Li, Jian Zhang, Sen Chen, Han Liu 等ISSTA 2024 · 被引用 8 次
- Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue ManagementLyuye Zhang, Jiahui Wu, Chengwei Liu, Kaixuan Li 等ISSTA 2025 · 被引用 3 次
- Minimizing Breaking Changes and Redundancy in Mitigating Technical Lag for Java ProjectsRui Lu, Lyuye Zhang, Kaixuan Li, Min Zhang 等ICSE 2026 · 被引用 1 次
相关 Paper
- Understanding the Threats of Upstream Vulnerabilities to Downstream Projects in the Maven EcosystemYulun Wu, Zeliang Yu, Ming Wen, Qiang Li 等ICSE 2023 · 被引用 41 次
- Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java ProjectsLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen 等ICSE 2023 · 被引用 19 次
- VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability AnalysisYutao Hu, Chaofan Li, Yueming Wu, Yifeng Cai 等NDSS 2026 · 被引用 1 次
- OSSFP: Precise and Scalable C/C++ Third-Party Library Detection using Fingerprinting FunctionsJiahui Wu, Zhengzi Xu, Wei Tang, Lyuye Zhang 等ICSE 2023 · 被引用 29 次
- Understanding the Limitations of C/C++ Binary Third-Party Library Detection Tool: An Empirical Study at ScaleChengyue Liu, Zhengzi Xu, Kaixuan Li, Jiahui Wu 等FSE 2026
