A Large-scale Fine-grained Analysis of Packages in Open-Source Software Ecosystems
Fuente:
arXiv
Salvato in:
| Autori principali: | Zhou, Xiaoyan, Liang, Feiran, Xie, Zhaojie, Lan, Yang, Niu, Wenjia, Liu, Jiqiang, Wang, Haining, Li, Qiang |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2024
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
An Analysis of Malicious Packages in Open-Source Software in the Wild
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024)
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024)
Tactics, Techniques, and Procedures (TTPs) in Interpreted Malware: A Zero-Shot Generation with Large Language Models
di: Zhang, Ying, et al.
Pubblicazione: (2024)
di: Zhang, Ying, et al.
Pubblicazione: (2024)
Automatically Generating Rules of Malicious Software Packages via Large Language Model
di: Zhang, XiangRui, et al.
Pubblicazione: (2025)
di: Zhang, XiangRui, et al.
Pubblicazione: (2025)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025)
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025)
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
di: Tatschner, Stefan, et al.
Pubblicazione: (2025)
di: Tatschner, Stefan, et al.
Pubblicazione: (2025)
SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
di: Pohl, Timo, et al.
Pubblicazione: (2025)
di: Pohl, Timo, et al.
Pubblicazione: (2025)
Sandboxing Adoption in Open Source Ecosystems
di: Alhindi, Maysara, et al.
Pubblicazione: (2024)
di: Alhindi, Maysara, et al.
Pubblicazione: (2024)
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025)
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025)
Unlocking Reproducibility: Automating re-Build Process for Open-Source Software
di: Hassanshahi, Behnaz, et al.
Pubblicazione: (2025)
di: Hassanshahi, Behnaz, et al.
Pubblicazione: (2025)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
di: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Pubblicazione: (2025)
di: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Pubblicazione: (2025)
DySec: A Machine Learning-based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
di: Mehedi, Sk Tanzir, et al.
Pubblicazione: (2025)
Securing the Software Package Supply Chain for Critical Systems
di: Murali, Ritwik, et al.
Pubblicazione: (2025)
di: Murali, Ritwik, et al.
Pubblicazione: (2025)
LLMs as Firmware Experts: A Runtime-Grown Tree-of-Agents Framework
di: Zhang, Xiangrui, et al.
Pubblicazione: (2025)
di: Zhang, Xiangrui, et al.
Pubblicazione: (2025)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
di: Wang, Fuwei, et al.
Pubblicazione: (2024)
di: Wang, Fuwei, et al.
Pubblicazione: (2024)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
di: Zheng, Xinyi, et al.
Pubblicazione: (2024)
di: Zheng, Xinyi, et al.
Pubblicazione: (2024)
ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2025)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
di: Cusick, James J.
Pubblicazione: (2025)
di: Cusick, James J.
Pubblicazione: (2025)
The Code the World Depends On: A First Look at Technology Makers' Open Source Software Dependencies
di: Patrick, Cadence, et al.
Pubblicazione: (2024)
di: Patrick, Cadence, et al.
Pubblicazione: (2024)
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
di: Ayala, Jessy, et al.
Pubblicazione: (2025)
di: Ayala, Jessy, et al.
Pubblicazione: (2025)
AutoFirm: Automatically Identifying Reused Libraries inside IoT Firmware at Large-Scale
di: Chen, YongLe, et al.
Pubblicazione: (2024)
di: Chen, YongLe, et al.
Pubblicazione: (2024)
Maven-Hijack: Software Supply Chain Attack Exploiting Packaging Order
di: Reyes, Frank, et al.
Pubblicazione: (2024)
di: Reyes, Frank, et al.
Pubblicazione: (2024)
TREBLE: Fast Software Updates by Creating an Equilibrium in an Active Software Ecosystem of Globally Distributed Stakeholders
di: Yim, Keun Soo, et al.
Pubblicazione: (2024)
di: Yim, Keun Soo, et al.
Pubblicazione: (2024)
Implicit Patterns in LLM-Based Binary Analysis
di: Li, Qiang, et al.
Pubblicazione: (2026)
di: Li, Qiang, et al.
Pubblicazione: (2026)
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
di: Ayala, Jessy, et al.
Pubblicazione: (2024)
di: Ayala, Jessy, et al.
Pubblicazione: (2024)
Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
di: Schorlemmer, Taylor R, et al.
Pubblicazione: (2024)
An Overview of Cyber Security Funding for Open Source Software
di: Ruohonen, Jukka, et al.
Pubblicazione: (2024)
di: Ruohonen, Jukka, et al.
Pubblicazione: (2024)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
di: Ponta, Serena E., et al.
Pubblicazione: (2018)
di: Ponta, Serena E., et al.
Pubblicazione: (2018)
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
di: Cheng, Yiran, et al.
Pubblicazione: (2024)
di: Cheng, Yiran, et al.
Pubblicazione: (2024)
Generating Proof-of-Vulnerability Tests to Help Enhance the Security of Complex Software
di: Kanchi, Shravya, et al.
Pubblicazione: (2026)
di: Kanchi, Shravya, et al.
Pubblicazione: (2026)
A Static Analysis of Popular C Packages in Linux
di: Ruohonen, Jukka, et al.
Pubblicazione: (2024)
di: Ruohonen, Jukka, et al.
Pubblicazione: (2024)
Fine-grained Data Access Control for Collaborative Process Execution on Blockchain
di: Marangone, Edoardo, et al.
Pubblicazione: (2022)
di: Marangone, Edoardo, et al.
Pubblicazione: (2022)
Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper) -- Extended Report
di: Shen, Mingjie, et al.
Pubblicazione: (2023)
di: Shen, Mingjie, et al.
Pubblicazione: (2023)
Cross-Ecosystem Vulnerability Analysis for Python Applications
di: Alexopoulos, Georgios, et al.
Pubblicazione: (2026)
di: Alexopoulos, Georgios, et al.
Pubblicazione: (2026)
Detecting Protracted Vulnerabilities in Open Source Projects
di: Sridharkumar, Arjun, et al.
Pubblicazione: (2026)
di: Sridharkumar, Arjun, et al.
Pubblicazione: (2026)
Mind the Gap: Evaluating LLMs for High-Level Malicious Package Detection vs. Fine-Grained Indicator Identification
di: Ryan, Ahmed, et al.
Pubblicazione: (2026)
di: Ryan, Ahmed, et al.
Pubblicazione: (2026)
SBOM Generation Tools in the Python Ecosystem: an In-Detail Analysis
di: Cofano, Serena, et al.
Pubblicazione: (2024)
di: Cofano, Serena, et al.
Pubblicazione: (2024)
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
di: Pecka, Nicholas, et al.
Pubblicazione: (2025)
di: Pecka, Nicholas, et al.
Pubblicazione: (2025)
A Manually-Curated Dataset of Fixes to Vulnerabilities of Open-Source Software
di: Ponta, Serena E., et al.
Pubblicazione: (2019)
di: Ponta, Serena E., et al.
Pubblicazione: (2019)
MalLoc: Toward Fine-grained Android Malicious Payload Localization via LLMs
di: Sun, Tiezhu, et al.
Pubblicazione: (2025)
di: Sun, Tiezhu, et al.
Pubblicazione: (2025)
SourceBroken: A large-scale analysis on the (un)reliability of SourceRank in the PyPI ecosystem
di: Montaruli, Biagio, et al.
Pubblicazione: (2025)
di: Montaruli, Biagio, et al.
Pubblicazione: (2025)
Documenti analoghi
-
An Analysis of Malicious Packages in Open-Source Software in the Wild
di: Zhou, Xiaoyan, et al.
Pubblicazione: (2024) -
Tactics, Techniques, and Procedures (TTPs) in Interpreted Malware: A Zero-Shot Generation with Large Language Models
di: Zhang, Ying, et al.
Pubblicazione: (2024) -
Automatically Generating Rules of Malicious Software Packages via Large Language Model
di: Zhang, XiangRui, et al.
Pubblicazione: (2025) -
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
di: Ruohonen, Jukka, et al.
Pubblicazione: (2025) -
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
di: Tatschner, Stefan, et al.
Pubblicazione: (2025)