V1SCAN: Discovering 1-day Vulnerabilities in Reused C/C++ Open-source Software Components Using Code Classification Techniques
Seunghoon Woo, Eunjin Choi, Heejo Lee, Hakjoo Oh
摘要
We present V1SCAN, an effective approach for discovering 1-day vulnerabilities in reused C/C++ open-source software (OSS) components. Reusing third-party OSS has many benefits, but can put the entire software at risk owing to the vulnerabilities they propagate. In mitigation, several techniques for detecting propagated vulnerabilities, which can be classified into version-and code-based approaches, have been proposed. However, state-of-the-art techniques unfortunately produce many false positives or negatives when OSS projects are reused with code modifications. In this paper, we show that these limitations can be addressed by improving version-and code-based approaches and synergistically combining them. By classifying reused code from OSS components, V1SCAN only considers vulnerabilities contained in the target program and filters out unused vulnerable code, thereby reducing false alarms produced by version-based approaches. V1SCAN improves the coverage of code-based approaches by classifying vulnerable code and then detecting vulnerabilities propagated with code changes in various code locations. Evaluation on GitHub popular C/C++ software showed that V1SCAN outperformed state-of-the-art vulnerability detection approaches by discovering 50% more vulnerabilities than they detected. In addition, V1SCAN reduced the false positive rate of the simple integration of existing version-and code-based approaches from 71% to 4% and the false negative rate from 33% to 7%. With V1SCAN, developers can detect propagated vulnerabilities with high accuracy, maintaining a secure software supply chain. Our approach. To overcome their shortcomings, we present V1SCAN, a novel approach for the precise and comprehensive discovery of 1-day security vulnerabilities propagated as a result of the reuse of C/C++ OSS components. We devise a new way to combine version-and code-based approaches to take full advantage of their strengths and avoid weaknesses. The main idea of V1SCAN, which is significantly distinguishable from existing approaches, is to detect propagated vulnerabilities using the code classification techniques.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- CyberGym: Evaluating AI Agents' Real-World Cybersecurity Capabilities at ScaleZhun Wang, Tianneng Shi, Jingxuan He, Matthew Cai 等ICLR 2026 · 被引用 83 次
- FIRE: Combining Multi-Stage Filtering with Taint Analysis for Scalable Recurring Vulnerability DetectionSiyue Feng, Yueming Wu, Wenjie Xue, Sikui Pan 等USENIX Security 2024 · 被引用 13 次
- CNEPS: A Precise Approach for Examining Dependencies among Third-Party C/C++ Open-Source ComponentsYoonjong Na, Seunghoon Woo, Joomyeong Lee, Heejo LeeICSE 2024 · 被引用 11 次
- VMud: Detecting Recurring Vulnerabilities with Multiple Fixing Functions via Function Selection and Semantic Equivalent Statement MatchingKaifeng Huang, Chenhao Lu, Yiheng Cao, Bihuan Chen 等CCS 2024 · 被引用 3 次
- Vulnerability-Affected Versions Identification: How Far Are We?Xingchu Chen, Chengwei Liu, Jialun Cao, Yang Xiao 等ASE 2025 · 被引用 3 次
它引用的顶会 Paper14
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 被引用 388 次
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 被引用 345 次
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Towards the Detection of Inconsistencies in Public Security Vulnerability ReportsYing Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing 等USENIX Security 2019 · 被引用 149 次
- Identifying Open-Source License Violation and 1-day Security Risk at Large ScaleRuian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim 等CCS 2017 · 被引用 126 次
相关 Paper
- VulSCA: A Community-Level SCA Approach for Accurate C/C++ Supply Chain Vulnerability AnalysisYutao Hu, Chaofan Li, Yueming Wu, Yifeng Cai 等NDSS 2026 · 被引用 1 次
- MOVERY: A Precise Approach for Modified Vulnerable Code Clone Discovery from Modified Open-Source Software ComponentsSeunghoon Woo, Hyunji Hong, Eunjin Choi, Heejo LeeUSENIX Security 2022
- Centris: A Precise and Scalable Approach for Identifying Modified Open-Source Software ReuseSeunghoon Woo, Sunghan Park, Seulbae Kim, Heejo Lee 等ICSE 2021 · 被引用 2 次
- Tiver: Identifying Adaptive Versions of C/C++ Third-Party Open-Source Components Using a Code Clustering TechniqueYoungjae Choi, Seunghoon WooICSE 2025 · 被引用 1 次
- Enhancing Security in Third-Party Library Reuse - Comprehensive Detection of 1-day Vulnerability through Code Patch AnalysisShangzhi Xu, Jialiang Dong, Weiting Cai, Juanru Li 等NDSS 2025
