Exploiting Library Vulnerability via Migration Based Automating Test Generation
Abstract
In software development, developers extensively utilize third-party libraries to avoid implementing existing functionalities. When a new third-party library vulnerability is disclosed, project maintainers need to determine whether their projects are affected by the vulnerability, which requires developers to invest substantial effort in assessment. However, existing tools face a series of issues: static analysis tools produce false alarms, dynamic analysis tools require existing tests and test generation tools have low success rates when facing complex vulnerabilities.
BibTeX
@inproceedings{Chen-al:ICSE24,
author = {Zirui Chen and
Xing Hu and
Xin Xia and
Yi Gao and
Tongtong Xu and
David Lo and
Xiaohu Yang},
title = {Exploiting Library Vulnerability via Migration Based Automating Test Generation},
booktitle = {ICSE},
pages = {228:1--228:12},
publisher = {{ACM}},
year = {2024},
}