Torna ai risultati
Scheda bibliografica · Consultazione e accesso
Preprint

Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories

Chen, Tianyu; Wang, Zeyu; Li, Lin; Li, Ding; Li, Zongyang; Chang, Xiaoning; Bian, Pan; Liang, Guangtai · Dagstuhl Research Online Publication Server · 2025

Materiale supplementare disponibile
Lettura rapida. Controlla i dati essenziali della risorsa e accedi al contenuto con il pulsante principale. La scheda mostra solo le informazioni necessarie per identificare, citare e aprire l’opera.

Accesso alla risorsa

Apri il contenuto dall’opzione principale o scegli un’altra fonte disponibile.

OpenAlex OpenAlex Works
Entrar por OpenAlex
Accesso principale

Materiale supplementare disponibile

El enlace apunta a material asociado, anexos, tablas, datos o página complementaria. No se marca como libro/texto completo.
Apri materiale

Riepilogo

Descripción general del contenido del recurso.

Functionality-specific vulnerabilities, which mainly occur in Application Programming Interfaces (APIs) with specific functionalities, are crucial for software developers to detect and avoid. When detecting individual functionality-specific vulnerabilities, the existing two categories of approaches are ineffective because they consider only the API bodies and are unable to handle diverse implementations of functionality-equivalent APIs. To effectively detect functionality-specific vulnerabilities, we propose APISS, the first approach to utilize API doc strings and signatures instead of API bodies. APISS first retrieves functionality-equivalent APIs for APIs with existing vulnerabilities and then migrates Proof-of-Concepts (PoCs) of the existing vulnerabilities for newly detected vulnerable APIs. To retrieve functionality-equivalent APIs, we leverage a Large Language Model for API embedding to improve the accuracy and address the effectiveness and scalability issues suffered by the existing approaches. To migrate PoCs of the existing vulnerabilities for newly detected vulnerable APIs, we design a semi-automatic schema to substantially reduce manual costs. We conduct a comprehensive evaluation to empirically compare APISS with four state-of-the-art approaches of detecting vulnerabilities and two state-of-the-art approaches of retrieving functionality-equivalent APIs. The evaluation subjects include 180 widely used Java repositories using 10 existing vulnerabilities, along with their PoCs. The results show that APISS effectively retrieves functionality-equivalent APIs, achieving a Top-1 Accuracy of 0.81 while the best of the baselines under comparison achieves only 0.55. APISS is highly efficient: the manual costs are within 10 minutes per vulnerability and the end-to-end runtime overhead of testing one candidate API is less than 2 hours. APISS detects 179 new vulnerabilities and receives 60 new CVE IDs, bringing high value to security practice.

Come citare

Elegí el formato que necesitás y copiá la referencia al portapapeles.

APA 7

Chen, T, Wang, Z, Li, L, Li, D, Li, Z, Chang, X, Bian, P, & Liang, G. (2025). Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories. Dagstuhl Research Online Publication Server. https://doi.org/10.4230/lipics.ecoop.2025.6

MLA

Chen, Tianyu, et al. Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories. Dagstuhl Research Online Publication Server, 2025. https://doi.org/10.4230/lipics.ecoop.2025.6.

Chicago

Chen, Tianyu, Zeyu Wang, Lin Li, Ding Li, Zongyang Li, Xiaoning Chang, Pan Bian, and Guangtai Liang. 2025. Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories. Dagstuhl Research Online Publication Server. https://doi.org/10.4230/lipics.ecoop.2025.6.

Harvard

Chen, T. et al. 2025, Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories, Dagstuhl Research Online Publication Server, available at: https://doi.org/10.4230/lipics.ecoop.2025.6 [Accessed 7 Aug. 2026].

Condividi e stampa

Salva la scheda, copia il link permanente o stampala in PDF.

Esporta riferimento

Esporta il record nei formati più comuni per usarlo con un gestore bibliografico.

Dettagli della risorsa

Informazioni bibliografiche utili per verificare che sia il materiale corretto.

Titolo
Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories
Autore / collaboratori
Chen, Tianyu; Wang, Zeyu; Li, Lin; Li, Ding; Li, Zongyang; Chang, Xiaoning; Bian, Pan; Liang, Guangtai
Editore
Dagstuhl Research Online Publication Server
Anno di pubblicazione
2025
Lingua
Inglés

Soggetti

Esplora risorse correlate a partire da questi soggetti.

Copiato