Reducing False Positives in Software Composition Analysis Using Reachability Analysis
Author
Dr. S. Subasree, Sanjayan V, Prabhat Bhunya G, Preethika KG, Sheik Musthafa M
Abstract
Open-source dependencies are a big part of modern software development, which makes software supply chain attacks more likely. Traditional Software Composition Analysis (SCA) tools find security holes by comparing library version metadata to databases of known vulnerabilities. This metadata-centric approach, on the other hand, produces a lot of false positives because vulnerabilities can be flagged even when the application code never calls the vulnerable functions. This project suggests an automated reachability analysis engine for dependency security that uses static analysis. The system follows execution paths from the entry points of an application to vulnerable external library functions by parsing the application's Abstract Syntax Tree (AST) and making a static call graph. This analysis puts vulnerabilities into two groups: reachable and effective, or unreachable and ineffective. This cuts down on alert fatigue by a lot and helps you focus on the most important remediation efforts.
Keywords
Reachability Analysis, Dependency Security, Static Application Security Testing, AST, Call Graph, Vulnerability Prioritization, OSV.dev, Python, Software Composition Analysis.
Full Text:
References
Python Software Foundation. Python AST Documentation. NetworkX Developers. NetworkX Documentation for Directed Graphs. OSV.dev. Open Source Vulnerabilities API Documentation. OWASP Foundation. Software Composition Analysis Overview. Common Vulnerabilities and Exposures (CVE) Database.