VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
Fuente:
arXiv
Guardado en:
| Autores principales: | Cheng, Yiran, Zhang, Ting, Shar, Lwin Khin, Yang, Shouguo, Dong, Chaopeng, Lo, David, Lv, Shichao, Shi, Zhiqiang, Sun, Limin |
|---|---|
| Formato: | Preprint |
| Publicado: |
2024
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
Revisiting Vulnerability Patch Identification on Data in the Wild
por: Irsan, Ivana Clairine, et al.
Publicado: (2026)
por: Irsan, Ivana Clairine, et al.
Publicado: (2026)
Mapping NVD Records to Their Vulnerability-fixing Commits: How Hard is It?
por: Nguyen, Huu Hung, et al.
Publicado: (2025)
por: Nguyen, Huu Hung, et al.
Publicado: (2025)
PatchSeeker: Mapping NVD Records to their Vulnerability-fixing Commits with LLM Generated Commits and Embeddings
por: Nguyen, Huu Hung, et al.
Publicado: (2025)
por: Nguyen, Huu Hung, et al.
Publicado: (2025)
Fixseeker: An Empirical Driven Graph-based Approach for Detecting Silent Vulnerability Fixes in Open Source Software
por: Cheng, Yiran, et al.
Publicado: (2025)
por: Cheng, Yiran, et al.
Publicado: (2025)
Semantics-Aligned, Curriculum-Driven, and Reasoning-Enhanced Vulnerability Repair Framework
por: Yang, Chengran, et al.
Publicado: (2025)
por: Yang, Chengran, et al.
Publicado: (2025)
CleanVul: Automatic Function-Level Vulnerability Detection in Code Commits Using LLM Heuristics
por: Li, Yikun, et al.
Publicado: (2024)
por: Li, Yikun, et al.
Publicado: (2024)
Beyond Function-Level Analysis: Context-Aware Reasoning for Inter-Procedural Vulnerability Detection
por: Li, Yikun, et al.
Publicado: (2026)
por: Li, Yikun, et al.
Publicado: (2026)
Towards Reliable LLM-Driven Fuzz Testing: Vision and Road Ahead
por: Cheng, Yiran, et al.
Publicado: (2025)
por: Cheng, Yiran, et al.
Publicado: (2025)
Virtualization-based Penetration Testing Study for Detecting Accessibility Abuse Vulnerabilities in Banking Apps in East and Southeast Asia
por: Minn, Wei, et al.
Publicado: (2026)
por: Minn, Wei, et al.
Publicado: (2026)
Static Security Vulnerability Scanning of Proprietary and Open-Source Software: An Adaptable Process with Variants and Results
por: Cusick, James J.
Publicado: (2025)
por: Cusick, James J.
Publicado: (2025)
Out of Distribution, Out of Luck: How Well Can LLMs Trained on Vulnerability Datasets Detect Top 25 CWE Weaknesses?
por: Li, Yikun, et al.
Publicado: (2025)
por: Li, Yikun, et al.
Publicado: (2025)
From Incomplete Architecture to Quantified Risk: Multimodal LLM-Driven Security Assessment for Cyber-Physical Systems
por: Huang, Shaofei, et al.
Publicado: (2026)
por: Huang, Shaofei, et al.
Publicado: (2026)
Patch2QL: Discover Cognate Defects in Open Source Software Supply Chain With Auto-generated Static Analysis Rules
por: Wang, Fuwei, et al.
Publicado: (2024)
por: Wang, Fuwei, et al.
Publicado: (2024)
Security Modelling for Cyber-Physical Systems: A Systematic Literature Review
por: Huang, Shaofei, et al.
Publicado: (2024)
por: Huang, Shaofei, et al.
Publicado: (2024)
Bayesian and Multi-Objective Decision Support for Real-Time Incident Mitigation in Critical Infrastructure
por: Huang, Shaofei, et al.
Publicado: (2025)
por: Huang, Shaofei, et al.
Publicado: (2025)
ACTISM: Threat-informed Dynamic Security Modelling for Automotive Systems
por: Huang, Shaofei, et al.
Publicado: (2024)
por: Huang, Shaofei, et al.
Publicado: (2024)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
por: Ponta, Serena E., et al.
Publicado: (2018)
por: Ponta, Serena E., et al.
Publicado: (2018)
BinEnhance: An Enhancement Framework Based on External Environment Semantics for Binary Code Search
por: Wang, Yongpan, et al.
Publicado: (2024)
por: Wang, Yongpan, et al.
Publicado: (2024)
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
por: Ruohonen, Jukka, et al.
Publicado: (2025)
por: Ruohonen, Jukka, et al.
Publicado: (2025)
VulEval: Towards Repository-Level Evaluation of Software Vulnerability Detection
por: Wen, Xin-Cheng, et al.
Publicado: (2024)
por: Wen, Xin-Cheng, et al.
Publicado: (2024)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
por: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Publicado: (2025)
por: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Publicado: (2025)
An Empirical Study of Vulnerable Package Dependencies in LLM Repositories
por: Liu, Shuhan, et al.
Publicado: (2025)
por: Liu, Shuhan, et al.
Publicado: (2025)
LLM-Driven Adaptive Source-Sink Identification and False Positive Mitigation for Static Analysis
por: Lin, Shiyin
Publicado: (2025)
por: Lin, Shiyin
Publicado: (2025)
IRIS: LLM-Assisted Static Analysis for Detecting Security Vulnerabilities
por: Li, Ziyang, et al.
Publicado: (2024)
por: Li, Ziyang, et al.
Publicado: (2024)
Investigating Vulnerability Disclosures in Open-Source Software Using Bug Bounty Reports and Security Advisories
por: Ayala, Jessy, et al.
Publicado: (2025)
por: Ayala, Jessy, et al.
Publicado: (2025)
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
por: Marquer, Yoann, et al.
Publicado: (2026)
por: Marquer, Yoann, et al.
Publicado: (2026)
UEFI Vulnerability Signature Generation using Static and Symbolic Analysis
por: Shafiuzzaman, Md, et al.
Publicado: (2024)
por: Shafiuzzaman, Md, et al.
Publicado: (2024)
Guiding Symbolic Execution with Static Analysis and LLMs for Vulnerability Discovery
por: Shafiuzzaman, Md, et al.
Publicado: (2026)
por: Shafiuzzaman, Md, et al.
Publicado: (2026)
A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security Features
por: Ayala, Jessy, et al.
Publicado: (2024)
por: Ayala, Jessy, et al.
Publicado: (2024)
Did You Forkget It? Detecting One-Day Vulnerabilities in Open-source ForksWith Global History Analysis
por: Lefeuvre, Romain, et al.
Publicado: (2025)
por: Lefeuvre, Romain, et al.
Publicado: (2025)
Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning
por: Ni, Ronghao, et al.
Publicado: (2026)
por: Ni, Ronghao, et al.
Publicado: (2026)
AutoVulnPHP: LLM-Powered Two-Stage PHP Vulnerability Detection and Automated Localization
por: Wang, Zhiqiang, et al.
Publicado: (2026)
por: Wang, Zhiqiang, et al.
Publicado: (2026)
CVE Breadcrumbs: Tracking Vulnerabilities Through Versioned Apache Libraries
por: Garcia, Derek, et al.
Publicado: (2025)
por: Garcia, Derek, et al.
Publicado: (2025)
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
por: Wen, Xin-Cheng, et al.
Publicado: (2024)
por: Wen, Xin-Cheng, et al.
Publicado: (2024)
CrossInspector: A Static Analysis Approach for Cross-Contract Vulnerability Detection
por: Chen, Xiao
Publicado: (2024)
por: Chen, Xiao
Publicado: (2024)
OpenSCV: An Open Hierarchical Taxonomy for Smart Contract Vulnerabilities
por: Vidal, Fernando Richter, et al.
Publicado: (2023)
por: Vidal, Fernando Richter, et al.
Publicado: (2023)
A Manually-Curated Dataset of Fixes to Vulnerabilities of Open-Source Software
por: Ponta, Serena E., et al.
Publicado: (2019)
por: Ponta, Serena E., et al.
Publicado: (2019)
QLPro: Automated Code Vulnerability Discovery via LLM and Static Code Analysis Integration
por: Hu, Junze, et al.
Publicado: (2025)
por: Hu, Junze, et al.
Publicado: (2025)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
por: Shifat, Fariha Tanjim, et al.
Publicado: (2026)
por: Shifat, Fariha Tanjim, et al.
Publicado: (2026)
Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
por: Ruan, Bonan, et al.
Publicado: (2025)
por: Ruan, Bonan, et al.
Publicado: (2025)
Ejemplares similares
-
Revisiting Vulnerability Patch Identification on Data in the Wild
por: Irsan, Ivana Clairine, et al.
Publicado: (2026) -
Mapping NVD Records to Their Vulnerability-fixing Commits: How Hard is It?
por: Nguyen, Huu Hung, et al.
Publicado: (2025) -
PatchSeeker: Mapping NVD Records to their Vulnerability-fixing Commits with LLM Generated Commits and Embeddings
por: Nguyen, Huu Hung, et al.
Publicado: (2025) -
Fixseeker: An Empirical Driven Graph-based Approach for Detecting Silent Vulnerability Fixes in Open Source Software
por: Cheng, Yiran, et al.
Publicado: (2025) -
Semantics-Aligned, Curriculum-Driven, and Reasoning-Enhanced Vulnerability Repair Framework
por: Yang, Chengran, et al.
Publicado: (2025)