kirancodes.me
To Proof Maintenance & Beyond!

Strengthening Supply Chain Security with Fine-grained Safe Patch Identification

Changhua Luo, Wei Meng, Shuai Wang

Abstract

Enhancing supply chain security is crucial, often involving the detection of patches in upstream software. However, current security patch analysis works yield relatively low recall rates (i.e., many security patches are missed). In this work, we offer a new solution to detect safe patches and assist downstream developers in patch propagation. Specifically, we develop SPatch to detect fine-grained safe patches. SPatch leverages fine-grained patch analysis and a new differential symbolic execution technique to analyze the functional impacts of code changes.

BibTeX
@inproceedings{Luo-al:ICSE24,
  author    = {Changhua Luo and
               Wei Meng and
               Shuai Wang},
  title     = {Strengthening Supply Chain Security with Fine-grained Safe Patch Identification},
  booktitle = {ICSE},
  pages     = {89:1--89:12},
  publisher = {{ACM}},
  year      = {2024},
}

Related papers