Software Composition Analysis for Vulnerability Detection: An Empirical Study on Java Projects

Author:

Zhao Lida1,Chen Sen2,Xu Zhengzi3,Liu Chengwei3,Zhang Lyuye3,Wu Jiahui3,Sun Jun4,Liu Yang3

Affiliation:

1. Singapore Management University, Nanyang Technological University, Singapore, Singapore

2. Tianjin University, Tianjin, China

3. Nanyang Technological University, Singapore, Singapore

4. Singapore Management University, Singapore, Singapore

Funder

Academic Research Fund Tier 3

National Cybersecurity R&D Programme

National Research Foundation, Singapore

Publisher

ACM

Reference68 articles.

1. 2021. Google Online Security Blog: Understanding the Impact of Apache Log4j Vulnerability. https://security.googleblog.com/2021/12/understanding-impact-of-apache-log4j.html 2021. Google Online Security Blog: Understanding the Impact of Apache Log4j Vulnerability. https://security.googleblog.com/2021/12/understanding-impact-of-apache-log4j.html

2. 2021. Maven Pom Descriptor Reference documentation. https://maven.apache.org/ref/3.8.5/maven-model/maven.html 2021. Maven Pom Descriptor Reference documentation. https://maven.apache.org/ref/3.8.5/maven-model/maven.html

3. 2021. OWASP Dependency-Check Project - OWASP. https://owasp.org/www-project-dependency-check/ 2021. OWASP Dependency-Check Project - OWASP. https://owasp.org/www-project-dependency-check/

4. 2021. Software dependencies: How to manage dependencies at scale | Why you should manage open source dependencies. https://snyk.io/series/open-source-security/software-dependencies/#managing-open-source-dependencies 2021. Software dependencies: How to manage dependencies at scale | Why you should manage open source dependencies. https://snyk.io/series/open-source-security/software-dependencies/#managing-open-source-dependencies

5. 2022. Component Analysis OWASP Foundation. https://owasp.org/www-community/Component_Analysis 2022. Component Analysis OWASP Foundation. https://owasp.org/www-community/Component_Analysis

Cited by 6 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. PatchFinder: A Two-Phase Approach to Security Patch Tracing for Disclosed Vulnerabilities in Open-Source Software;Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis;2024-09-11

2. GRACE: Empowering LLM-based software vulnerability detection with graph structure and in-context learning;Journal of Systems and Software;2024-06

3. Vul4Java: A Java OSS vulnerability identification method based on a two-stage analysis;International Conference on Algorithms, Software Engineering, and Network Security;2024-04-26

4. Vulnerability Root Cause Function Locating For Java Vulnerabilities;Proceedings of the 2024 IEEE/ACM 46th International Conference on Software Engineering: Companion Proceedings;2024-04-14

5. Empirical Analysis of Vulnerabilities Life Cycle in Golang Ecosystem;Proceedings of the IEEE/ACM 46th International Conference on Software Engineering;2024-04-12

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3