科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ The Eurasia Proceedings of Science Technology Engineering and Mathematics2026-07-31· Computer science

Improving Accuracy of OWASP Dependency-Check Through Optimized CPE Matching to Reduce False Positives and False Negatives

Wahyu Francesco Toldo Hutabarat, Yani Widyani

原始摘要(英文原文)· Original abstract
In today’s digital era, the use of open-source dependencies in modern software development has become commonplace. However, this practice increases security risks due to vulnerabilities hidden within the open-source components being used. Software Composition Analysis (SCA) is one of the approaches that can be utilized to detect and mitigate the risks arising from the use of open-source dependencies. Nevertheless, existing SCA tools still face a fundamental challenge in the form of false positives (reported vulnerabilities that are not actually relevant) and false negatives (vulnerabilities that remain undetected), which can degrade the accuracy of detection results and hinder security analysis as well as mitigation decisions. This study focuses on improving the accuracy of one widely used SCA tool, OWASP Dependency-Check, by highlighting one of its main sources of error: the Common Platform Enumeration (CPE) matching process between project dependencies and vulnerability entries in the Common Vulnerabilities and Exposures (CVE) database. The objectives of this research are to analyze CPE matching error patterns, design optimization mechanisms to improve the matching process, and evaluate the impact of these optimizations.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Improving Accuracy of OWASP Dependency-Check Through Optimized CPE Matching to Reduce False Positives and False Negatives — 科研速览 Science Skim