SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Lingxiang, Wang, Fu, Quanzhi, Song, Wenjia, Deng, Gelei, Liu, Yi, Williams, Dan, Zhang, Ying
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918103039868928
author Lingxiang, Wang
Fu, Quanzhi
Song, Wenjia
Deng, Gelei
Liu, Yi
Williams, Dan
Zhang, Ying
author_facet Lingxiang, Wang
Fu, Quanzhi
Song, Wenjia
Deng, Gelei
Liu, Yi
Williams, Dan
Zhang, Ying
contents The integration of open-source third-party library dependencies in Java development introduces significant security risks when these libraries contain known vulnerabilities. Existing Software Composition Analysis (SCA) tools struggle to effectively detect vulnerable API usage from these libraries due to limitations in understanding API usage semantics and computational challenges in analyzing complex codebases, leading to inaccurate vulnerability alerts that burden development teams and delay critical security fixes. To address these challenges, we proposed SAVANT by leveraging two insights: proof-of-vulnerability test cases demonstrate how vulnerabilities can be triggered in specific contexts, and Large Language Models (LLMs) can understand code semantics. SAVANT combines semantic preprocessing with LLM-powered context analysis for accurate vulnerability detection. SAVANT first segments source code into meaningful blocks while preserving semantic relationships, then leverages LLM-based reflection to analyze API usage context and determine actual vulnerability impacts. Our evaluation on 55 real-world applications shows that SAVANT achieves 83.8% precision, 73.8% recall, 69.0% accuracy, and 78.5% F1-score, outperforming state-of-the-art SCA tools.
format Preprint
id arxiv_https___arxiv_org_abs_2506_17798
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
Lingxiang, Wang
Fu, Quanzhi
Song, Wenjia
Deng, Gelei
Liu, Yi
Williams, Dan
Zhang, Ying
Software Engineering
Cryptography and Security
The integration of open-source third-party library dependencies in Java development introduces significant security risks when these libraries contain known vulnerabilities. Existing Software Composition Analysis (SCA) tools struggle to effectively detect vulnerable API usage from these libraries due to limitations in understanding API usage semantics and computational challenges in analyzing complex codebases, leading to inaccurate vulnerability alerts that burden development teams and delay critical security fixes. To address these challenges, we proposed SAVANT by leveraging two insights: proof-of-vulnerability test cases demonstrate how vulnerabilities can be triggered in specific contexts, and Large Language Models (LLMs) can understand code semantics. SAVANT combines semantic preprocessing with LLM-powered context analysis for accurate vulnerability detection. SAVANT first segments source code into meaningful blocks while preserving semantic relationships, then leverages LLM-based reflection to analyze API usage context and determine actual vulnerability impacts. Our evaluation on 55 real-world applications shows that SAVANT achieves 83.8% precision, 73.8% recall, 69.0% accuracy, and 78.5% F1-score, outperforming state-of-the-art SCA tools.
title SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
topic Software Engineering
Cryptography and Security
url https://arxiv.org/abs/2506.17798