GANADI:通过基于关键函数的聚类揭示C/C++开源软件复用谱系以增强供应链安全
GANADI: Uncovering C/C++ OSS Reuse Genealogies via Pivotal Function-Based Clustering to Enhance Supply Chain Security
- Korea University(高丽大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
GANADI通过基于关键函数聚类下游项目并推断复用方向,构建C/C++开源软件复用谱系,在20个项目中达到84.85%精确率和95.76%召回率,并发现48个未修补漏洞,显著提升供应链安全。
AI中文摘要:
我们提出了GANADI,一种系统性的方法,用于识别C/C++开源软件(OSS)的复用谱系,以增强软件供应链安全。理解OSS复用谱系对于提高软件物料清单(SBOM)的完整性以及优先进行跨供应链的安全修复至关重要。尽管现有方法能够识别项目中被复用的组件和漏洞,但它们无法追踪通过中间项目的OSS复用路径,限制了其在保护供应链生态系统方面的有效性。为解决这一局限,GANADI通过基于源自原始代码的共享特征(称为关键函数)对下游项目进行聚类,然后在每个聚类内推断项目之间的复用方向,从而构建复用谱系。当应用于20个广泛复用的OSS项目(涉及超过1,500条传播路径)时,GANADI在识别复用谱系方面达到了84.85%的精确率和95.76%的召回率,优于现有方法(现有方法最多仅达到23.21%的召回率)。利用OSS复用谱系进行漏洞检测,我们在现实世界的流行C/C++项目中识别出48个未修补的漏洞。其中,23个漏洞在我们负责任披露后得到了修补(包括分配了一个CVE编号),这证明了基于谱系的漏洞管理的实际影响。
英文摘要:
We present GANADI, a systematic approach for identifying C/C++ OSS reuse genealogies to enhance software supply chain security. Understanding OSS reuse genealogy is crucial for improving SBOM completeness and prioritizing security remediation across supply chains. Although existing approaches can identify reused compo- nents and vulnerabilities within a project, they fail to trace OSS reuse paths through intermediate projects, limiting their effectiveness in securing supply chain ecosystems. To address this limitation, GANADI constructs reuse genealogies by clustering downstream projects based on shared characteristics of origin-derived code (called pivotal functions), and then inferring reuse direction among the projects within each cluster. When applied to 20 widely reused OSS projects with over 1,500 propagation paths, GANADI achieved 84.85% precision and 95.76% recall in identifying reuse genealogies, outperforming existing approaches that achieved at most 23.21% recall. Leveraging OSS reuse genealogy for vulnerability detection, we identified 48 unpatched vulnerabilities in real-world popular C/C++ projects. Among them, 23 were patched following our responsible disclosure (including one CVE ID assigned), demonstrating the practical impact of genealogy-based vulnerability management.