Identifying Affected Libraries and Their Ecosystems for Open Source Software Vulnerabilities
Susheng Wu, Wenyan Song, Kaifeng Huang, Bihuan Chen, Xin Peng · 2024
Software composition analysis (SCA) tools have been widely adopted to identify vulnerable libraries used in software applications. Such SCA tools depend on a vulnerability database to know affected libraries of each vulnerability. However, it is labor-intensive and error prone for a security team to manually maintain the vulnerability database. While several approaches adopt extreme multi-label learning to predict affected libraries for vulnerabilities, they are practically ineffective due to the limited library labels and the unawareness of ecosystems.