| 注册
首页|期刊导航|计算机应用与软件|一种面向开源软件漏洞的补丁查找与解析方法

一种面向开源软件漏洞的补丁查找与解析方法

许聪颖 陈碧欢 赵文耘

计算机应用与软件2025,Vol.42Issue(4):1-7,32,8.
计算机应用与软件2025,Vol.42Issue(4):1-7,32,8.DOI:10.3969/j.issn.1000-386x.2025.04.001

一种面向开源软件漏洞的补丁查找与解析方法

A METHOD FOR FINDING AND PARSING PATCHES FOR OPEN SOURCE SOFTWARE VULNERABILITIES

许聪颖 1陈碧欢 1赵文耘1

作者信息

  • 1. 复旦大学软件学院 上海 200438||上海市数据科学重点实验室 上海 200438
  • 折叠

摘要

Abstract

Patches,as a valuable piece of information for security-related tasks,are often missing in security advisories.In this article,we propose an automated approach,named PatFinder,to find and parse patches for open source software(OSS)vulnerabilities.First,PatFinder identified commits from numerous vulnerability-related references.Then,PatFinder selected patches based on code changes of identified commits and a weighted voting mechanism.Finally,based on designed patch parsing methods,metadata of patches(i.e.,paths of modified files and names of functions)was obtained.Our experiment has shown that PatFinder can achieve a coverage of 73.10%and a recall of 0.802,significantly improving the coverage and recall of existing approaches.

关键词

软件安全/漏洞/补丁

Key words

Software security/Vulnerability/Patch

分类

计算机与自动化

引用本文复制引用

许聪颖,陈碧欢,赵文耘..一种面向开源软件漏洞的补丁查找与解析方法[J].计算机应用与软件,2025,42(4):1-7,32,8.

基金项目

国家自然科学基金项目(61802067). (61802067)

计算机应用与软件

OA北大核心

1000-386X

访问量0
|
下载量0
段落导航相关论文