VFArchē: A Dual-Mode Framework for Locating Vulnerable Functions in Open-Source Software

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Zhang, Lyuye, Zhang, Jian, Li, Kaixuan, Wang, Chong, Liu, Chengwei, Wu, Jiahui, Chen, Sen, Zheng, Yaowen, Liu, Yang
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866915357248192512
author Zhang, Lyuye
Zhang, Jian
Li, Kaixuan
Wang, Chong
Liu, Chengwei
Wu, Jiahui
Chen, Sen
Zheng, Yaowen
Liu, Yang
author_facet Zhang, Lyuye
Zhang, Jian
Li, Kaixuan
Wang, Chong
Liu, Chengwei
Wu, Jiahui
Chen, Sen
Zheng, Yaowen
Liu, Yang
contents Software Composition Analysis (SCA) has become pivotal in addressing vulnerabilities inherent in software project dependencies. In particular, reachability analysis is increasingly used in Open-Source Software (OSS) projects to identify reachable vulnerabilities (e.g., CVEs) through call graphs, enabling a focus on exploitable risks. Performing reachability analysis typically requires the vulnerable function (VF) to track the call chains from downstream applications. However, such crucial information is usually unavailable in modern vulnerability databases like NVD. While directly extracting VF from modified functions in vulnerability patches is intuitive, patches are not always available. Moreover, our preliminary study shows that over 26% of VF do not exist in the modified functions. Meanwhile, simply ignoring patches to search vulnerable functions suffers from overwhelming noises and lexical gaps between descriptions and source code. Given that almost half of the vulnerabilities are equipped with patches, a holistic solution that handles both scenarios with and without patches is required. To meet real-world needs and automatically localize VF, we present VFArchē, a dual-mode approach designed for disclosed vulnerabilities, applicable in scenarios with or without available patch links. The experimental results of VFArchē on our constructed benchmark dataset demonstrate significant efficacy regarding three metrics, achieving 1.3x and 1.9x Mean Reciprocal Rank over the best baselines for Patch-present and Patch-absent modes, respectively. Moreover, VFArchē has proven its applicability in real-world scenarios by successfully locating VF for 43 out of 50 latest vulnerabilities with reasonable efforts and significantly reducing 78-89% false positives of SCA tools.
format Preprint
id arxiv_https___arxiv_org_abs_2506_18050
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle VFArchē: A Dual-Mode Framework for Locating Vulnerable Functions in Open-Source Software
Zhang, Lyuye
Zhang, Jian
Li, Kaixuan
Wang, Chong
Liu, Chengwei
Wu, Jiahui
Chen, Sen
Zheng, Yaowen
Liu, Yang
Software Engineering
Software Composition Analysis (SCA) has become pivotal in addressing vulnerabilities inherent in software project dependencies. In particular, reachability analysis is increasingly used in Open-Source Software (OSS) projects to identify reachable vulnerabilities (e.g., CVEs) through call graphs, enabling a focus on exploitable risks. Performing reachability analysis typically requires the vulnerable function (VF) to track the call chains from downstream applications. However, such crucial information is usually unavailable in modern vulnerability databases like NVD. While directly extracting VF from modified functions in vulnerability patches is intuitive, patches are not always available. Moreover, our preliminary study shows that over 26% of VF do not exist in the modified functions. Meanwhile, simply ignoring patches to search vulnerable functions suffers from overwhelming noises and lexical gaps between descriptions and source code. Given that almost half of the vulnerabilities are equipped with patches, a holistic solution that handles both scenarios with and without patches is required. To meet real-world needs and automatically localize VF, we present VFArchē, a dual-mode approach designed for disclosed vulnerabilities, applicable in scenarios with or without available patch links. The experimental results of VFArchē on our constructed benchmark dataset demonstrate significant efficacy regarding three metrics, achieving 1.3x and 1.9x Mean Reciprocal Rank over the best baselines for Patch-present and Patch-absent modes, respectively. Moreover, VFArchē has proven its applicability in real-world scenarios by successfully locating VF for 43 out of 50 latest vulnerabilities with reasonable efforts and significantly reducing 78-89% false positives of SCA tools.
title VFArchē: A Dual-Mode Framework for Locating Vulnerable Functions in Open-Source Software
topic Software Engineering
url https://arxiv.org/abs/2506.18050