Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Zhang, Lyuye, Liu, Chengwei, Wu, Jiahui, Zhang, Shiyang, Liu, Chengyue, Xu, Zhengzi, Chen, Sen, Liu, Yang
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915217909219328
author Zhang, Lyuye
Liu, Chengwei
Wu, Jiahui
Zhang, Shiyang
Liu, Chengyue
Xu, Zhengzi
Chen, Sen
Liu, Yang
author_facet Zhang, Lyuye
Liu, Chengwei
Wu, Jiahui
Zhang, Shiyang
Liu, Chengyue
Xu, Zhengzi
Chen, Sen
Liu, Yang
contents The prevalent use of third-party libraries (TPLs) in modern software development introduces significant security and compliance risks, necessitating the implementation of Software Composition Analysis (SCA) to manage these threats. However, the accuracy of SCA tools heavily relies on the quality of the integrated feature database to cross-reference with user projects. While under the circumstance of the exponentially growing of open-source ecosystems and the integration of large models into software development, it becomes even more challenging to maintain a comprehensive feature database for potential TPLs. To this end, after referring to the evolution of LLM applications in terms of external data interactions, we propose the first framework of DB-Less SCA, to get rid of the traditional heavy database and embrace the flexibility of LLMs to mimic the manual analysis of security analysts to retrieve identical evidence and confirm the identity of TPLs by supportive information from the open Internet. Our experiments on two typical scenarios, native library identification for Android and copy-based TPL reuse for C/C++, especially on artifacts that are not that underappreciated, have demonstrated the favorable future for implementing database-less strategies in SCA.
format Preprint
id arxiv_https___arxiv_org_abs_2503_22576
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
Zhang, Lyuye
Liu, Chengwei
Wu, Jiahui
Zhang, Shiyang
Liu, Chengyue
Xu, Zhengzi
Chen, Sen
Liu, Yang
Software Engineering
The prevalent use of third-party libraries (TPLs) in modern software development introduces significant security and compliance risks, necessitating the implementation of Software Composition Analysis (SCA) to manage these threats. However, the accuracy of SCA tools heavily relies on the quality of the integrated feature database to cross-reference with user projects. While under the circumstance of the exponentially growing of open-source ecosystems and the integration of large models into software development, it becomes even more challenging to maintain a comprehensive feature database for potential TPLs. To this end, after referring to the evolution of LLM applications in terms of external data interactions, we propose the first framework of DB-Less SCA, to get rid of the traditional heavy database and embrace the flexibility of LLMs to mimic the manual analysis of security analysts to retrieve identical evidence and confirm the identity of TPLs by supportive information from the open Internet. Our experiments on two typical scenarios, native library identification for Android and copy-based TPL reuse for C/C++, especially on artifacts that are not that underappreciated, have demonstrated the favorable future for implementing database-less strategies in SCA.
title Drop the Golden Apples: Identifying Third-Party Reuse by DB-Less Software Composition Analysis
topic Software Engineering
url https://arxiv.org/abs/2503.22576