Fine-Grained Network Analysis for Modern Software Ecosystems

被引:10
|
作者
Boldi, Paolo [1 ]
Gousios, Georgios [2 ]
机构
[1] Univ Milan, Dipartimento Informat, Milan, Italy
[2] Delft Univ Technol, Dept Software Technol, Delft, Netherlands
基金
欧盟地平线“2020”;
关键词
Software reuse; security breaches; network analysis;
D O I
10.1145/3418209
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modern software development is increasingly dependent on components, libraries, and frameworks coming from third-party vendors or open-source suppliers and made available through a number of platforms (or forges). This way of writing software puts an emphasis on reuse and on composition, commoditizing the services that modern applications require. On the other hand, bugs and vulnerabilities in a single library living in one such ecosystem can affect, directly or by transitivity, a huge number of other libraries and applications. Currently, only product-level information on library dependencies is used to contain this kind of danger, but this knowledge often reveals itself too imprecise to lead to effective (and possibly automated) handling policies. We will discuss how fine-grained function-level dependencies can greatly improve reliability and reduce the impact of vulnerabilities on the whole software ecosystem.
引用
收藏
页数:14
相关论文
共 50 条
  • [31] Fine-grained Construction of Semantic Technology Network for Technology Evolution Analysis
    Li, Xiaoman
    Song, Hongyan
    Zhang, Xuefu
    Xu, Qian
    PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND APPLICATION ENGINEERING (CSAE2019), 2019,
  • [32] Fine-Grained Analysis of Financial Tweets
    Chen, Chung-Chi
    Huang, Hen-Hsen
    Chen, Hsin-Hsi
    COMPANION PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2018 (WWW 2018), 2018, : 1943 - 1949
  • [33] A FINE-GRAINED ANALYSIS ON DISTRIBUTION SHIFT
    Wiles, Olivia
    Gowal, Sven
    Stimberg, Florian
    Rebuffi, Sylvestre-Alvise
    Ktena, Ira
    Dvijotham, Krishnamurthy
    Cemgil, Taylan
    ICLR 2022 - 10th International Conference on Learning Representations, 2022,
  • [34] VOLUNTARY IMAGINATION: A FINE-GRAINED ANALYSIS
    Canavotto, Ilaria
    Berto, Francesco
    Giordani, Alessandro
    REVIEW OF SYMBOLIC LOGIC, 2022, 15 (02): : 362 - 387
  • [35] Fine-grained analysis of change couplings
    Fluri, B
    Gall, HC
    Pinzger, M
    FIFTH IEEE INTERNATIONAL WORKSHOP ON SOURCE CODE ANALYSIS AND MANIPULATION, PROCEEDINGS, 2005, : 66 - 74
  • [36] FINE-GRAINED COLOUR DISCRIMINATION WITHOUT FINE-GRAINED COLOUR
    Gert, Joshua
    AUSTRALASIAN JOURNAL OF PHILOSOPHY, 2015, 93 (03) : 602 - 605
  • [37] Fine-grained Traffic Classification Based on Improved Residual Convolutional Network in Software Defined Networks
    Su, Chang
    Liu, Yanqing
    Xie, Xianzhong
    IEEE LATIN AMERICA TRANSACTIONS, 2023, 21 (04) : 565 - 572
  • [38] Fine-Grained Control-Flow Integrity for Kernel Software
    Ge, Xinyang
    Talele, Nirupama
    Payer, Mathias
    Jaeger, Trent
    1ST IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, 2016, : 179 - 194
  • [39] Fine-Grained Fingerprinting Threats to Software-Defined Networks
    Zhang, Minjian
    Hou, Jianwei
    Zhang, Ziqi
    Shi, Wenchang
    Qin, Bo
    Liang, Bin
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS / 11TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING / 14TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2017, : 128 - 135
  • [40] Fine-Grained Hardware/Software Methodology for Process Migration in MPSoCs
    Li, Tuo
    Ambrose, Jude Angelo
    Parameswaran, Sri
    2012 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD), 2012, : 508 - 515