Jul 2026· The eurasia proceedings of science, technology, engineering & mathematics· Vol 40, pp. 193-201· 0 citations· 21 references
TL;DR
This study focuses on improving the accuracy of one widely used SCA tool, OWASP Dependency-Check, by highlighting one of its main sources of error: the Common Platform Enumeration (CPE) matching process between project dependencies and vulnerability entries in the Common Vulnerabilities and Exposures (CVE) database.
Abstract
In today’s digital era, the use of open-source dependencies in modern software development has become commonplace. However, this practice increases security risks due to vulnerabilities hidden within the open-source components being used. Software Composition Analysis (SCA) is one of the approaches that can be utilized to detect and mitigate the risks arising from the use of open-source dependencies. Nevertheless, existing SCA tools still face a fundamental challenge in the form of false positives (reported vulnerabilities that are not actually relevant) and false negatives (vulnerabilities that remain undetected), which can degrade the accuracy of detection results and hinder security analysis as well as mitigation decisions. This study focuses on improving the accuracy of one widely used SCA tool, OWASP Dependency-Check, by highlighting one of its main sources of error: the Common Platform Enumeration (CPE) matching process between project dependencies and vulnerability entries in the Common Vulnerabilities and Exposures (CVE) database. The objectives of this research are to analyze CPE matching error patterns, design optimization mechanisms to improve the matching process, and evaluate the impact of these optimizations.
ReDoS vulnerabilities are a type of denial of service software weakness that occurs when a regex is used to validate user-supplied input. In some cases, the regex matching process can take exponential time, leading to a denial of service. In this study, we examine and compare the effectiveness of five publicly-availabl...
N'Zolieh Ismaël Mahassadi, Raphaël Khoury, J. Vallé et al.· 0 citations
SNIPTEST is an execution-based warning triage framework that generates and fuzzes compiled code slices centered around static-analysis warnings that employs a layer-by-layer slicing strategy, incrementally expanding context around the target location to validate potential vulnerabilities with increasing precision.
Aniruddhan Murali, Noble Saji Mathews, Mahmoud Alfadel et al.· IEEE Transactions on Softwar...· 0 citations
The findings support the claim that BF is a more structured and automation-friendly framework than CWE, and exploration reveals specific gaps in BF, including under-specified guidance on attributes.
Mohammad Nazmul Hoque, Shaswata Mitra, Subash Neupane et al.· 0 citations
VICBench enables robust evaluation of vulnerability detection approaches and shows that state-of-the-art algorithms V-SZZ and LLM4SZZ achieve only 33.3%-40.1% F1, confirming that using existing approaches still entails significant manual effort.
Jin Lu, Xuening Han, Yan Zhong et al.· 0 citations
A security assessment on 75 FastAPI backends generated by three contemporary LLMs revealed a disconnect between functional correctness and secure logic, which is interpreted as a review-risk pattern, which is called the human-in-the-loop paradox.
Abdul Ali Khan, S. Rauti, T. Mäkilä· IEEE Access· 0 citations
Prototype pollution is a critical class of taint-style vulnerabilities in JavaScript programs, enabling attackers to tamper with object prototypes and thereby alter program behavior in unexpected and often dangerous ways. Despite its severity, existing detection techniques struggle with excessive false positives and po...
De-Zhen Kong, Pei-Sen Yao, Jia-Kun Liu et al.· ACM Transactions on Software...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.