A Practical Solution to Systematically Monitor Inconsistencies in SBOM-based Vulnerability Scanners
Fuente:
arXiv
Saved in:
| Main Authors: | Rosso, Martin, Jaffar, Muhammad Asad Jahangir, Brighente, Alessandro, Conti, Mauro |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
by: Sorger, Tom, et al.
Published: (2026)
by: Sorger, Tom, et al.
Published: (2026)
The Impact of SBOM Generators on Vulnerability Assessment in Python: A Comparison and a Novel Approach
by: Benedetti, Giacomo, et al.
Published: (2024)
by: Benedetti, Giacomo, et al.
Published: (2024)
VeriSBOM: Secure and Verifiable SBOM Sharing Via Zero-Knowledge Proofs
by: Castiglione, Gianpietro, et al.
Published: (2026)
by: Castiglione, Gianpietro, et al.
Published: (2026)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
by: Safronov, Vadim, et al.
Published: (2025)
by: Safronov, Vadim, et al.
Published: (2025)
Automating SBOM Generation with Zero-Shot Semantic Similarity
by: Pereira, Devin, et al.
Published: (2024)
by: Pereira, Devin, et al.
Published: (2024)
SBOM Generation Tools in the Python Ecosystem: an In-Detail Analysis
by: Cofano, Serena, et al.
Published: (2024)
by: Cofano, Serena, et al.
Published: (2024)
VDGraph: A Graph-Theoretic Approach to Unlock Insights from SBOM and SCA Data
by: Xia, Howell, et al.
Published: (2025)
by: Xia, Howell, et al.
Published: (2025)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
by: Bufalino, Jacopo, et al.
Published: (2025)
by: Bufalino, Jacopo, et al.
Published: (2025)
Unpacking Security Scanners for GitHub Actions Workflows
by: Fares, Madjda, et al.
Published: (2026)
by: Fares, Madjda, et al.
Published: (2026)
AndroScanner: Automated Backend Vulnerability Detection for Android Applications
by: Dandu, Harini
Published: (2026)
by: Dandu, Harini
Published: (2026)
AI-Based Software Vulnerability Detection: A Systematic Literature Review
by: Shimmi, Samiha, et al.
Published: (2025)
by: Shimmi, Samiha, et al.
Published: (2025)
When Labels Are Scarce: A Systematic Mapping of Label-Efficient Code Vulnerability Detection
by: Khalal, Noor, et al.
Published: (2026)
by: Khalal, Noor, et al.
Published: (2026)
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
by: Jayalath, Raveen Kanishka, et al.
Published: (2024)
Unlocking User-oriented Pages: Intention-driven Black-box Scanner for Real-world Web Applications
by: Wang, Weizhe, et al.
Published: (2025)
by: Wang, Weizhe, et al.
Published: (2025)
A Solution toward Transparent and Practical AI Regulation: Privacy Nutrition Labels for Open-source Generative AI-based Applications
by: Si, Meixue, et al.
Published: (2024)
by: Si, Meixue, et al.
Published: (2024)
LineBreaker: Finding Token-Inconsistency Bugs with Large Language Models
by: Chen, Hongbo, et al.
Published: (2024)
by: Chen, Hongbo, et al.
Published: (2024)
When Specifications Meet Reality: Uncovering API Inconsistencies in Ethereum Infrastructure
by: Ma, Jie, et al.
Published: (2026)
by: Ma, Jie, et al.
Published: (2026)
Security study based on the Chatgptplugin system: ldentifying Security Vulnerabilities
by: Ren, Ruomai
Published: (2025)
by: Ren, Ruomai
Published: (2025)
A Ground-Truth-Based Evaluation of Vulnerability Detection Across Multiple Ecosystems
by: Mandl, Peter, et al.
Published: (2026)
by: Mandl, Peter, et al.
Published: (2026)
Bridging the Gap: A Study of AI-based Vulnerability Management between Industry and Academia
by: Wan, Shengye, et al.
Published: (2024)
by: Wan, Shengye, et al.
Published: (2024)
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
by: Kumar, Shree Hari Bittugondanahalli Indra, et al.
Published: (2025)
Fixing Security Vulnerabilities with AI in OSS-Fuzz
by: Zhang, Yuntong, et al.
Published: (2024)
by: Zhang, Yuntong, et al.
Published: (2024)
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
by: Li, Zhen, et al.
Published: (2024)
by: Li, Zhen, et al.
Published: (2024)
Improving Smart Contract Security with Contrastive Learning-based Vulnerability Detection
by: Chen, Yizhou, et al.
Published: (2024)
by: Chen, Yizhou, et al.
Published: (2024)
ACFIX: Guiding LLMs with Mined Common RBAC Practices for Context-Aware Repair of Access Control Vulnerabilities in Smart Contracts
by: Zhang, Lyuye, et al.
Published: (2024)
by: Zhang, Lyuye, et al.
Published: (2024)
KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities
by: Ruan, Bonan, et al.
Published: (2024)
by: Ruan, Bonan, et al.
Published: (2024)
Vulnerability-Hunter: An Adaptive Feature Perception Attention Network for Smart Contract Vulnerabilities
by: Chen, Yizhou
Published: (2024)
by: Chen, Yizhou
Published: (2024)
Game Rewards Vulnerabilities: Software Vulnerability Detection with Zero-Sum Game and Prototype Learning
by: Wen, Xin-Cheng, et al.
Published: (2024)
by: Wen, Xin-Cheng, et al.
Published: (2024)
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
by: Zhang, Fangyuan, et al.
Published: (2024)
by: Zhang, Fangyuan, et al.
Published: (2024)
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
by: Ponta, Serena E., et al.
Published: (2018)
by: Ponta, Serena E., et al.
Published: (2018)
VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM
by: Cheng, Yiran, et al.
Published: (2024)
by: Cheng, Yiran, et al.
Published: (2024)
VulZoo: A Comprehensive Vulnerability Intelligence Dataset
by: Ruan, Bonan, et al.
Published: (2024)
by: Ruan, Bonan, et al.
Published: (2024)
An Empirical Study on the Security Vulnerabilities of GPTs
by: Wu, Tong, et al.
Published: (2025)
by: Wu, Tong, et al.
Published: (2025)
Deep Learning Aided Software Vulnerability Detection: A Survey
by: Uddin, Md Nizam, et al.
Published: (2025)
by: Uddin, Md Nizam, et al.
Published: (2025)
SHERLOCK: A Deep Learning Approach To Detect Software Vulnerabilities
by: Jawwadh, Saadh, et al.
Published: (2025)
by: Jawwadh, Saadh, et al.
Published: (2025)
MiniScope: Automated UI Exploration and Privacy Inconsistency Detection of MiniApps via Two-phase Iterative Hybrid Analysis
by: Wang, Shenao, et al.
Published: (2024)
by: Wang, Shenao, et al.
Published: (2024)
Designing Robust API Monitoring Solutions
by: D'Elia, Daniele Cono, et al.
Published: (2020)
by: D'Elia, Daniele Cono, et al.
Published: (2020)
Smart Contract Fuzzing Towards Profitable Vulnerabilities
by: Kong, Ziqiao, et al.
Published: (2025)
by: Kong, Ziqiao, et al.
Published: (2025)
Fast and Accurate Silent Vulnerability Fix Retrieval
by: Liu, Xueqing, et al.
Published: (2025)
by: Liu, Xueqing, et al.
Published: (2025)
Similar Items
-
zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets
by: Sorger, Tom, et al.
Published: (2026) -
The Impact of SBOM Generators on Vulnerability Assessment in Python: A Comparison and a Novel Approach
by: Benedetti, Giacomo, et al.
Published: (2024) -
VeriSBOM: Secure and Verifiable SBOM Sharing Via Zero-Knowledge Proofs
by: Castiglione, Gianpietro, et al.
Published: (2026) -
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024) -
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
by: Safronov, Vadim, et al.
Published: (2025)