VulPA: Detecting Semantically Recurring Vulnerabilities with Multi-object Typestate Analysis
Abstract
Detecting semantically recurring vulnerabilities with similar root causes remains a challenge due to the complex interactions between multiple variables. This paper introduces V ul PA, a novel approach for precisely identifying such vulnerabilities through complex inter-procedural data and control flows across multiple objects. V ul PA tackles this challenge in two steps: 1) Defining root causes with a Vulnerability Pattern Description Language (VPDL) that specifies variable relations and bug-triggering operations, and 2) Detecting these patterns using an inter-procedural multi-object analysis that tracks dataflows and variable interactions. Built on the H eros IFDS framework, V ul PA was evaluated on 26 Java applications using rules from 34 CVEs. It identified 90 new vulnerabilities (23.7% false positive rate), outperforming existing tools (R e D e B ug , VUDDY, S ourcerer CC, PH unter , PPT4J, F low D roid , and IDE al ), which collectively found only 13. V ul PA effectively uncovers complex vulnerabilities missed by state-of-the-art tools.
BibTeX
@article{Cao-al:FSE25,
author = {Liqing Cao and
Haofeng Li and
Chenghang Shi and
Jie Lu and
Haining Meng and
Lian Li and
Jingling Xue},
title = {{VulPA:} Detecting Semantically Recurring Vulnerabilities with Multi-object Typestate Analysis},
journal = {{PACMSE}},
volume = {2},
number = {{FSE}},
pages = {2430--2453},
year = {2025},
}