V-SZZ: Automatic Identification of Version Ranges Affected by CVE Vulnerabilities
Lingfeng Bao, Xin Xia, Ahmed E. Hassan, Xiaohu Yang
摘要
Vulnerabilities publicly disclosed in the National Vulnerability Database (NVD) are assigned with CVE (Common Vulnerabilities and Exposures) IDs and associated with specific software versions. Many organizations, including IT companies and government, heavily rely on the disclosed vulnerabilities in NVD to mitigate their security risks. Once a software is claimed as vulnerable by NVD, these organizations would examine the presence of the vulnerable versions of the software and assess the impact on themselves. However, the version information about vulnerable software in NVD is not always reliable. Nguyen et al. find that the version information of many CVE vulnerabilities is spurious and propose an approach based on the original SZZ algorithm (i.e., an approach to identify bug-introducing commits) to assess the software versions affected by CVE vulnerabilities. However, SZZ algorithms are designed for common bugs, while vulnerabilities and bugs are different. Many bugs are introduced by a recent bug-fixing commit, but vulnerabilities are usually introduced in their initial versions. Thus, the current SZZ algorithms often fail to identify the inducing commits for vulnerabilities. Therefore, in this study, we propose an approach based on an improved SZZ algorithm to refine software versions affected by CVE vulnerabilities. Our proposed SZZ algorithm leverages the line mapping algorithms to identify the earliest commit that modified the vulnerable lines, and then considers these commits to be the vulnerability-inducing commits, as opposed to the previous SZZ algorithms that assume the commits that last modified the buggy lines as the inducing commits. To evaluate our proposed approach, we manually annotate the true inducing commits and verify the vulnerable versions for 172 CVE vulnerabilities with fixing commits from two publicly available datasets with five C/C++ and 41 Java projects, respectively.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper18
- CHRONOS: Time-Aware Zero-Shot Identification of Libraries from Vulnerability ReportsYunbo Lyu, Thanh Le-Cong, Hong Jin Kang, Ratnadira Widyasari 等ICSE 2023 · 被引用 20 次
- Neural SZZ AlgorithmLingxiao Tang, Lingfeng Bao, Xin Xia, Zhongdong HuangASE 2023 · 被引用 9 次
- Identifying Affected Libraries and Their Ecosystems for Open Source Software VulnerabilitiesSusheng Wu, Wenyan Song, Kaifeng Huang, Bihuan Chen 等ICSE 2024 · 被引用 9 次
- SymBisect: Accurate Bisection for Fuzzer-Exposed VulnerabilitiesZheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou 等USENIX Security 2024 · 被引用 7 次
- Precise (Un)Affected Version Analysis for Web VulnerabilitiesYoukun Shi, Yuan Zhang, Tianhan Luo, Xiangyu Mao 等ASE 2022 · 被引用 7 次
它引用的顶会 Paper6
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid ResponseZhen Huang, Mariana D'Angelo, Dhaval Miyani, David LieS&P 2016 · 被引用 59 次
- A large-scale empirical study on vulnerability distribution within projects and the lessons learnedBingchang Liu, Guozhu Meng, Wei Zou, Qi Gong 等ICSE 2020 · 被引用 43 次
- Evaluating SZZ Implementations Through a Developer-informed OracleGiovanni Rosa, Luca Pascarella, Simone Scalabrino, Rosalia Tufano 等ICSE 2021 · 被引用 42 次
- A Differential Testing Approach for Evaluating Abstract Syntax Tree Mapping AlgorithmsYuanrui Fan, Xin Xia, David Lo, Ahmed E. Hassan 等ICSE 2021 · 被引用 18 次
相关 Paper
- V0Finder: Discovering the Correct Origin of Publicly Reported Software VulnerabilitiesSeunghoon Woo, Dongwook Lee, Sunghan Park, Heejo Lee 等USENIX Security 2021 · 被引用 36 次
- Accurate Identification of the Vulnerability-Introducing Commit based on Differential Analysis of Patching PatternsQixuan Guo, Yongzhong HeNDSS 2026 · 被引用 1 次
- Vulnerability-Affected Versions Identification: How Far Are We?Xingchu Chen, Chengwei Liu, Jialun Cao, Yang Xiao 等ASE 2025 · 被引用 3 次
- Locating the Security Patches for Disclosed OSS Vulnerabilities with Vulnerability-Commit Correlation RankingXin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao 等CCS 2021 · 被引用 43 次
- Towards the Detection of Inconsistencies in Public Security Vulnerability ReportsYing Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing 等USENIX Security 2019 · 被引用 149 次
