Vulnerability analysis using pre-computed reachability information for software components
Techniques are disclosed for performing vulnerability analysis based on pre-computed reachability information of software components. A system may obtain a first software component, perform call-path tracing from functions of the first software component to at least one function of a second software component to identify functions that are reachable via at least one call path originating in the first software component as reachable functions, and compute, in association with the first software component, a pre-computed reachable dataset comprising the reachable functions. The system may obtain a project dependency listing that identifies software components including the first software component to be used by a software project and generate a vulnerability report based at least in part on the pre-computed reachable dataset, the vulnerability report identifying functions of the reachable functions of the first software component that are vulnerable.
1 . A computer-implemented method comprising:
obtaining a first software component for reachability analysis;
performing call-path tracing from functions of the first software component to at least one function of a second software component to identify functions that are reachable via at least one call path originating in the first software component as reachable functions of the first software component, the reachable functions of the first software component including the at least one function of the second software component;
computing, in association with the first software component, a pre-computed reachable dataset comprising the reachable functions of the first software component;
obtaining a project dependency listing that identifies a plurality of software components used by a software project, the plurality of software components including the first software component; and
generating a vulnerability report for the software project based at least in part on the pre-computed reachable dataset of the first software component, the vulnerability report identifying one or more functions of the reachable functions of the first software component that are vulnerable as vulnerable functions.
2 . The computer-implemented method of claim 1 , wherein generating the vulnerability report for the software project further comprises retrieving, from a vulnerability database, specific vulnerability details for the reachable functions of the first software component.
3 . The computer-implemented method of claim 1 , wherein the performing the call-path tracing and computing the pre-computed reachable dataset are performed separately for a plurality of different versions of the first software component to compute, for the plurality of different versions, distinct pre-computed reachable datasets.
4 . The computer-implemented method of claim 1 , wherein performing the call-path tracing continues, from the second software component, to at least one dependent software component of the second software component and the vulnerability report excludes vulnerable functions of the at least one dependent software component that are not reachable via call paths originating in the first software component.
5 . The computer-implemented method of claim 1 , wherein performing the call-path tracing continues, from the second software component, to at least one dependent software component of the second software component and comprises locating potential entry points in direct dependencies of the first software component and calculating reachability from these entry points.
6 . The computer-implemented method of claim 5 , wherein performing the call-path tracing from functions of the first software component comprises, when call paths within a private dependency of the first software component are unavailable, flattening direct dependencies of the private dependency by treating entry points of direct dependencies of the private dependency as additional entry points for the call-path tracing.
7 . The computer-implemented method of claim 1 , further comprising:
building, based on the call-path tracing, a graph of reachable calls that spans a network of interconnected software components by tracing calls that propagate between the interconnected software components, the building comprising:
adding directly accessible calls of the first software component that are accessible when invoking the first software component to the graph; and
linking, in the graph, transitively accessible calls in the interconnected software components to the directly accessible calls;
wherein the network of interconnected software components includes the first software component and the second software component;
wherein the transitively accessible calls are calls that are directly or indirectly invoked by directly accessible calls of the first software component; and
wherein the call-path tracing is based at least in part on the graph of reachable calls.
8 . The computer-implemented method of claim 1 , further comprising:
populating a database of vulnerable functions with descriptions of security vulnerabilities for functions of a network of interconnected software components that includes the first software component and the second software component,
wherein:
populating the database comprises creating records for functions that are included in a list of common vulnerabilities and exposures (CVE) records and annotating the records with additional information about vulnerabilities found in the functions; and
the performing the call-path tracing is based at least in part on the database of vulnerable functions.
9 . The computer-implemented method of claim 1 , wherein:
the performing the call-path tracing and the computing the pre-computed reachable dataset are performed, prior to the obtaining the project dependency listing, for software components of a plurality of different software components to store respective pre-computed reachable datasets in association with individual software components of the plurality of different software components.
10 . The computer-implemented method of claim 1 , wherein the call-path tracing is performed using static analysis of source code, bytecode, or binary artifacts.
11 . The computer-implemented method of claim 1 , wherein the first software component is a library.
12 . A system comprising:
at least one processor; and
a non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the system to:
obtain a first software component for reachability analysis;
perform call-path tracing from functions of the first software component to at least one function of a second software component to identify, as reachable functions of the first software component, functions that are reachable via at least one call path originating in the first software component, the reachable functions of the first software component including the at least one function of the second software component;
compute, in association with the first software component, a pre-computed reachable dataset comprising the reachable functions of the first software component;
obtain a project dependency listing that identifies a plurality of software components used by a software project, the plurality of software components including the first software component; and
generate a vulnerability report for the software project based at least in part on the pre-computed reachable dataset of the first software component, the vulnerability report identifying vulnerable functions of the reachable functions of the first software component that are vulnerable.
13 . The system of claim 12 , wherein generating the vulnerability report for the software project further comprises retrieving specific vulnerability details for the reachable functions of the first software component from a vulnerability database.
14 . The system of claim 12 , wherein obtaining the first software component, performing the call-path tracing, and computing the pre-computed reachable dataset are performed separately for a plurality of different versions of the first software component to compute distinct pre-computed reachable datasets for the plurality of different versions.
15 . The system of claim 12 , wherein performing the call-path tracing continues, from the second software component, to at least one dependent software component of the second software component and the vulnerability report excludes vulnerable functions of the at least one dependent software component that are not reachable via call paths originating in the first software component.
16 . The system of claim 12 , wherein performing the call-path tracing continues, from the second software component, to at least one dependent software component of the second software component and comprises locating potential entry points in direct dependencies of the first software component and calculating reachability from these entry points.
17 . The system of claim 16 , wherein performing the call-path tracing from functions of the first software component comprises, when call paths within a private dependency of the first software component are unavailable, flattening direct dependencies of the private dependency by treating entry points of direct dependencies of the private dependency as additional entry points for the call-path tracing.
18 . The system of claim 12 , wherein the instructions further cause the system to:
build, based on the call-path tracing, a graph of reachable calls that spans a network of interconnected software components by tracing calls that propagate between the interconnected software components, the building comprising:
adding directly accessible calls of the first software component that are accessible when invoking the first software component to the graph; and
linking, in the graph, transitively accessible calls in the interconnected software components to the directly accessible calls;
wherein the network of interconnected software components includes the first software component and the second software component;
wherein the transitively accessible calls are calls that are directly or indirectly invoked by directly accessible calls of the first software component; and
wherein the call-path tracing is based at least in part on the graph of reachable calls.
19 . The system of claim 12 , wherein the instructions further cause the system to:
populate a database of vulnerable functions with descriptions of security vulnerabilities for functions of a network of interconnected software components that includes the first software component and the second software component, wherein populating the database comprises creating records for functions that are included in a list of common vulnerabilities and exposures (CVE) records and annotating the records with additional information about vulnerabilities found in the functions; and
wherein the performing the call-path tracing is based at least in part on the database of vulnerable functions.
20 . The system of claim 12 , wherein:
the performing the call-path tracing and the computing the pre-computed reachable dataset are performed, prior to the obtaining the project dependency listing, for software components of a plurality of different software components to store respective pre-computed reachable datasets in association with individual software components of the plurality of different software components.