节点文献

基于函数调用图分析的C/C++第三方库漏洞影响分析方法

C/C++ THIRD PARTY LIBRARY’S VULNERABILITY IMPACT ANALYSIS METHOD BASED ON CALL GRAPH ANALYSIS

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 吴舒仪; 陈碧欢; 王颖; 赵文耘;

【Author】 Wu Shuyi;Chen Bihuan;Wang Ying;Zhao Wenyun;School of Computer Science, Fudan University;State Grid Information and Telecommunication Group Co., Ltd.;

【机构】 复旦大学计算科学技术学院; 国网信息通信产业集团有限公司;

【摘要】 针对工业界软件成分分析工具第三方库漏洞扫描粒度过粗而导致的假阳性误报问题,提出一种基于函数调用图分析的C/C++第三方库漏洞影响分析方法。该方法分析第三方库漏洞是否通过软件项目的函数调用图可达判断第三方库漏洞是否会对软件项目产生影响;提供细粒度的、函数级别的、更加准确的第三方库漏洞影响分析。实验表明,该方法的查准率为94%,查全率为77%,能减少约80%由于扫描粒度过粗而导致的误报。

【Abstract】 To eliminate the false positives caused by coarse-grained impact analysis of existing software component analysis tools, a C/C++ third party library(TPL)’s vulnerability impact analysis method based on call graph analysis is proposed. The method evaluated the impact of TPL vulnerabilities by checking whether the TPL vulnerabilities were reachable through the call graph of the software, which provided a fine-grained, method-level and accurate TPL vulnerability impact analysis. The experiments show that the method achieves a precision of 94% and a recall of 77%, and reduces 80% of the false positives caused by coarse-grained impact analysis.

  • 【文献出处】 计算机应用与软件 ,Computer Applications and Software , 编辑部邮箱 ,2025年06期
  • 【分类号】TP312.1;TP309;TP311.52
  • 【下载频次】11
节点文献中: 

本文链接的文献网络图示:

本文的引文网络