Page 144 - 《软件学报》2026年第7期
P. 144
徐美秋 等: CAnalyzer: 面向 C/C++源代码的软件成分分析技术 2829
[12] Yuan ZM, Feng MY, Li F, Ban G, Xiao Y, Wang SY, Tang Q, Su H, Yu CD, Xu JH, Piao AH, Xuey J, Huo W. B2SFinder: Detecting
open-source software reuse in cots software. In: Proc. of the 34th IEEE/ACM Int’l Conf. on Automated Software Engineering (ASE). San
Diego: IEEE, 2019. 1038–1049. [doi: 10.1109/ASE.2019.00100]
[13] Woo S, Park S, Kim S, Lee H, Oh H. CENTRIS: A precise and scalable approach for identifying modified open-source software reuse.
In: Proc. of the 43rd IEEE/ACM Int’l Conf. on Software Engineering (ICSE). Madrid: IEEE, 2021. 860–872. [doi: 10.1109/ICSE43902.
2021.00083]
[14] Jiang L, Yuan HC, Tang QY, Nie S, Wu S, Zhang YQ. Third-party library dependency for large-scale SCA in the C/C++ ecosystem: How
far are we? In: Proc. of the 32nd ACM SIGSOFT Int’l Symp. on Software Testing and Analysis. Seattle: ACM, 2023. 1383–1395. [doi:
10.1145/3597926.3598143]
[15] Wu JH, Xu ZZ, Tang W, Zhang L, Wu YM, Liu CY, Sun KR, Zhao LD, Liu Y. OSSFP: Precise and scalable C/C++ third-party library
detection using fingerprinting functions. In: Proc. of the 45th IEEE/ACM Int’l Conf. on Software Engineering (ICSE). Melbourne:
IEEE, 2023. 270–282. [doi: 10.1109/ICSE48619.2023.00034]
[16] Snyk. 2023 state of open source security report. 2023. https://go.snyk.io/state-of-open-source-security-report-2023.html
[17] Xia BM, Bi TT, Xing ZC, Lu QH, Zhu LM. An empirical study on software bill of materials: Where we stand and the road ahead. In:
Proc. of the 45th IEEE/ACM Int’l Conf. on Software Engineering (ICSE). Melbourne: IEEE, 2023. 2630–2642. [doi: 10.1109/ICSE48619.
2023.00219]
[18] Zimmermann M, Staicu CA, Tenny C, Pradel M. Small world with high risks: A study of security threats in the npm ecosystem. In: Proc.
of the 28th USENIX Security Symp. Santa Clara: USENIX, 2019. 995–1010.
[19] Sonatype. State of the software supply chain. 2025. https://www.sonatype.com/state-of-the-software-supply-chain/Introduction
[20] Libaiff. aifftools. 2007. https://sourceforge.net/projects/aifftools/files/
[21] SourceForge. The complete software platform. 2025. https://sourceforge.net/
[22] GNU. Termcap. 2025. ftp://ftp.gnu.org/gnu/termcap
[23] Google. SwiftShader. 2025. https://github.com/google/swiftshader
[24] SourceForge Repository. 7-Zip. 2025. https://sourceforge.net/projects/sevenzip/files/7-Zip/
[25] ip7z. 7zip. 2025. https://github.com/ip7z/7zip
[26] p7zip-project. p7zip. 2025. https://github.com/p7zip-project/p7zip
[27] LinuxDevices. Cisco settles with FSF on GPL violations. 2009. https://linuxdevices.org/cisco-settles-with-fsf-on-gpl-violations/
[28] ZDNet. VMware sued for failure to comply with Linux license. 2015. https://www.zdnet.com/article/vmware-sued-for-failure-to-comply-
with-linuxs-license/
[29] Tang W, Xu ZZ, Liu CW, Wu JH, Yang SG, Li Y, Luo P, Liu Y. Towards understanding third-party library dependency in C/C++
ecosystem. In: Proc. of the 37th IEEE/ACM Int’l Conf. on Automated Software Engineering. Rochester: ACM, 2022. 106. [doi: 10.1145/
3551349.3560432]
[30] Universal Ctags. Ctags. 2025. https://github.com/universal-ctags/
[31] Oliver J, Cheng C, Chen YG. TLSH—A locality sensitive hash. In: Proc. of the 4th Cybercrime and Trustworthy Computing Workshop.
Sydney: IEEE, 2013. 7–13. [doi: 10.1109/CTC.2013.9]
[32] GitHub Repository. Freetype. 2025. https://github.com/freetype/freetype
[33] GCC, the GNU compiler collection. 2025. https://gcc.gnu.org/
[34] F-score. 2025. https://en.wikipedia.org/wiki/F-score
[35] Page L, Brin S. The PageRank citation ranking: Bringing order to the Web. Stanford InfoLab, 1999. [doi: 10.1007/978-3-319-08789-4_10]
[36] BYVoid. OpenCC. 2025. https://github.com/BYVoid/OpenCC
[37] pybind. pybind11. 2025. https://github.com/pybind/pybind11
[38] Anigmetov A. hera. 2025. https://github.com/anigmetov/her
[39] Debian Salsa. r-cran-fs. 2025. https://salsa.debian.org/r-pkg-team/r-cran-fs
[40] Facebook. Hermes. 2025. https://github.com/facebook/hermes
[41] Tree-sitter. tree-sitter. 2025. https://github.com/tree-sitter/tree-sitte
[42] Miyani D, Huang Z, Lie D. BinPro: A tool for binary source code provenance. arXiv:1711.00830, 2017.
[43] Jiang L, An JW, Huang HH, Tang QY, Nie S, Wu S, Zhang YQ. BinaryAI: Binary software composition analysis via intelligent binary
source code matching. In: Proc. of the 46th IEEE/ACM Int’l Conf. on Software Engineering. Lisbon: ACM, 2024. 224. [doi: 10.1145/
3597503.3639100]
[44] OWASP. OWASP dependency-track. 2025. https://owasp.org/www-project-dependency-track

