Unveiling the Characteristics and Impact of Security Patch Evolution
Zifan Xie, Ming Wen, Zichao Wei, Hai Jin
摘要
The number of disclosed vulnerabilities in open-source projects has been increasing steadily over the years, and thus it is important to deploy patches to repair vulnerabilities in a timely manner. However, due to the widespread reuse and customization of open-source software, there are often multiple versions or branches of the same project that co-exist in the ecosystem. Therefore, it is often challenging and tricky to guarantee that an exposed vulnerability can be repaired thoroughly. Driven by this, plenty of 1-day vulnerability analysis tools have been proposed recently, such as function-level vulnerability detection and patch presence test tools. Despite the fact that code evolution is common for open-source projects, existing analysis tools often neglect the important fact that the patched code is also constantly evolving. In this study, we take the first look to systematically investigate the phenomenon of security patch evolution in open-source projects. In particular, we performed extensive experiments on a large-scale dataset containing 1,046 distinct CVEs with 2,633 patches collected from popular open-source projects (e.g., linux, openssl). This study reveals interesting yet important findings with respect to the aspects of patch evolution frequency, patch evolution patterns, and the evolution impact on downstream 1-day vulnerability analysis tools. We believe that this study can shed important light on future researches on patch analysis.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper23
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin 等CCS 2017 · 被引用 682 次
- Asm2Vec: Boosting Static Representation Robustness for Binary Clone Search against Code Obfuscation and Compiler OptimizationSteven H. H. Ding, Benjamin C. M. Fung, Philippe CharlandS&P 2019 · 被引用 447 次
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- jTrans: jump-aware transformer for binary code similarity detectionHao Wang, Wenjie Qu, Gilad Katz, Wenyu Zhu 等ISSTA 2022 · 被引用 139 次
相关 Paper
- Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software SecurityAlfusainey Jallow, Michael Schilling, Michael Backes, Sven BugielS&P 2024 · 被引用 6 次
- V1SCAN: Discovering 1-day Vulnerabilities in Reused C/C++ Open-source Software Components Using Code Classification TechniquesSeunghoon Woo, Eunjin Choi, Heejo Lee, Hakjoo OhUSENIX Security 2023
- Understanding the Practice of Security Patch Management across Multiple Branches in OSS ProjectsXin Tan, Yuan Zhang, Jiajun Cao, Kun Sun 等WWW 2022 · 被引用 19 次
- A Comprehensive Empirical Analysis of Patch Presence Testing: Capabilities, Limitations, and Paths ForwardXiaobei Zhang, Yaowen Zheng, Wu Luo, Shijun Zhao 等ISSTA 2026
- SPIDER: Enabling Fast Patch Propagation In Related Software RepositoriesAravind Machiry, Nilo Redini, Eric Camellini, Christopher Kruegel 等S&P 2020 · 被引用 39 次
