Journal of Information Security Reserach ›› 2026, Vol. 12 ›› Issue (E1): 104-107.
Previous Articles Next Articles
Online:2026-09-04
Published:2026-09-04
焦涵,王勇,吴沁玥
| [1] ZHANG F, FAN L, CHEN S, et al. Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries[J]. IEEE Transactions on Software Engineering, 2024, 50(11): 2906-2920 . [2] XU S, DONG J, CAI W, et al. Enhancing Security in Third-Party Library Reuse – Comprehensive Detection of 1-day Vulnerability through Code Patch Analysis [EB/OL]. 2024[2025-12-23]. https://arxiv.org/pdf/2411. 19648. [3] CHENG Y, ZHANG T, SHAR L K, et al.Vercation: Precise Vulnerable Open-Source Software Version Identification Based on Static Analysis and LLM[J]. IEEE Transactions on Software Engineering, 2026, 52(2): 376-394. [4] Sun L .Securing Supply Chains in Open Source Ecosystems: Methodologies for Determining Version Numbers of Components Without Package Management Files[J]. Journal of Computing and Electronic Information Management, 2024, 12(1):32-36. [5] SHEN W, SHEN G, WANG Y, et al.AI-Driven Open Source Component Security Analysis and Intelligent Vulnerability Prediction Model [EB/OL]. 2025[2026-04-30]. http://ieeexplore.ieee.org/document/11136289/. [6] 胡飞,陈昊,王媛,等. 基于图网络的Java反序列化漏洞检测方法[J]. 计算机技术与发展,2023,33(5):122-129. [7] NOCERA S, VEGAS S, SCANNIELLO G, et al.Software Composition Analysis and Supply Chain Security in Apache Projects: an Empirical Study [EB/OL]. 2025[2026-04-30]. https://ieeexplore.ieee.org/document/11025577. [8] 陈克豪,程伟,丁荪,等. 开源组件安全面对安全左移带来的挑战研究[J]. 软件导刊,2022,21(9):135-140. [9] ZHENG X, WEI C, WANG S, et al. Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments [C].PROCEEDINGS OF 2024 39TH ACM/IEEE INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2024. Canada,2024:1990-2001. |
| Viewed | ||||||
|
Full text |
|
|||||
|
Abstract |
|
|||||