Page 144 - 《软件学报》2026年第7期
P. 144

徐美秋 等: CAnalyzer: 面向  C/C++源代码的软件成分分析技术                                         2829


                 [12]   Yuan ZM, Feng MY, Li F, Ban G, Xiao Y, Wang SY, Tang Q, Su H, Yu CD, Xu JH, Piao AH, Xuey J, Huo W. B2SFinder: Detecting
                     open-source software reuse in cots software. In: Proc. of the 34th IEEE/ACM Int’l Conf. on Automated Software Engineering (ASE). San
                     Diego: IEEE, 2019. 1038–1049. [doi: 10.1109/ASE.2019.00100]
                 [13]   Woo S, Park S, Kim S, Lee H, Oh H. CENTRIS: A precise and scalable approach for identifying modified open-source software reuse.
                     In: Proc. of the 43rd IEEE/ACM Int’l Conf. on Software Engineering (ICSE). Madrid: IEEE, 2021. 860–872. [doi: 10.1109/ICSE43902.
                     2021.00083]
                 [14]   Jiang L, Yuan HC, Tang QY, Nie S, Wu S, Zhang YQ. Third-party library dependency for large-scale SCA in the C/C++ ecosystem: How
                     far are we? In: Proc. of the 32nd ACM SIGSOFT Int’l Symp. on Software Testing and Analysis. Seattle: ACM, 2023. 1383–1395. [doi:
                     10.1145/3597926.3598143]
                 [15]   Wu JH, Xu ZZ, Tang W, Zhang L, Wu YM, Liu CY, Sun KR, Zhao LD, Liu Y. OSSFP: Precise and scalable C/C++ third-party library
                     detection  using  fingerprinting  functions.  In:  Proc.  of  the  45th  IEEE/ACM  Int’l  Conf.  on  Software  Engineering  (ICSE).  Melbourne:
                     IEEE, 2023. 270–282. [doi: 10.1109/ICSE48619.2023.00034]
                 [16]   Snyk. 2023 state of open source security report. 2023. https://go.snyk.io/state-of-open-source-security-report-2023.html
                 [17]   Xia BM, Bi TT, Xing ZC, Lu QH, Zhu LM. An empirical study on software bill of materials: Where we stand and the road ahead. In:
                     Proc. of the 45th IEEE/ACM Int’l Conf. on Software Engineering (ICSE). Melbourne: IEEE, 2023. 2630–2642. [doi: 10.1109/ICSE48619.
                     2023.00219]
                 [18]   Zimmermann M, Staicu CA, Tenny C, Pradel M. Small world with high risks: A study of security threats in the npm ecosystem. In: Proc.
                     of the 28th USENIX Security Symp. Santa Clara: USENIX, 2019. 995–1010.
                 [19]   Sonatype. State of the software supply chain. 2025. https://www.sonatype.com/state-of-the-software-supply-chain/Introduction
                 [20]   Libaiff. aifftools. 2007. https://sourceforge.net/projects/aifftools/files/
                 [21]   SourceForge. The complete software platform. 2025. https://sourceforge.net/
                 [22]   GNU. Termcap. 2025. ftp://ftp.gnu.org/gnu/termcap
                 [23]   Google. SwiftShader. 2025. https://github.com/google/swiftshader
                 [24]   SourceForge Repository. 7-Zip. 2025. https://sourceforge.net/projects/sevenzip/files/7-Zip/
                 [25]   ip7z. 7zip. 2025. https://github.com/ip7z/7zip
                 [26]   p7zip-project. p7zip. 2025. https://github.com/p7zip-project/p7zip
                 [27]   LinuxDevices. Cisco settles with FSF on GPL violations. 2009. https://linuxdevices.org/cisco-settles-with-fsf-on-gpl-violations/
                 [28]   ZDNet. VMware sued for failure to comply with Linux license. 2015. https://www.zdnet.com/article/vmware-sued-for-failure-to-comply-
                     with-linuxs-license/
                 [29]   Tang W, Xu ZZ, Liu CW, Wu JH, Yang SG, Li Y, Luo P, Liu Y. Towards understanding third-party library dependency in C/C++
                     ecosystem. In: Proc. of the 37th IEEE/ACM Int’l Conf. on Automated Software Engineering. Rochester: ACM, 2022. 106. [doi: 10.1145/
                     3551349.3560432]
                 [30]   Universal Ctags. Ctags. 2025. https://github.com/universal-ctags/
                 [31]   Oliver J, Cheng C, Chen YG. TLSH—A locality sensitive hash. In: Proc. of the 4th Cybercrime and Trustworthy Computing Workshop.
                     Sydney: IEEE, 2013. 7–13. [doi: 10.1109/CTC.2013.9]
                 [32]   GitHub Repository. Freetype. 2025. https://github.com/freetype/freetype
                 [33]   GCC, the GNU compiler collection. 2025. https://gcc.gnu.org/
                 [34]   F-score. 2025. https://en.wikipedia.org/wiki/F-score
                 [35]   Page L, Brin S. The PageRank citation ranking: Bringing order to the Web. Stanford InfoLab, 1999. [doi: 10.1007/978-3-319-08789-4_10]
                 [36]   BYVoid. OpenCC. 2025. https://github.com/BYVoid/OpenCC
                 [37]   pybind. pybind11. 2025. https://github.com/pybind/pybind11
                 [38]   Anigmetov A. hera. 2025. https://github.com/anigmetov/her
                 [39]   Debian Salsa. r-cran-fs. 2025. https://salsa.debian.org/r-pkg-team/r-cran-fs
                 [40]   Facebook. Hermes. 2025. https://github.com/facebook/hermes
                 [41]   Tree-sitter. tree-sitter. 2025. https://github.com/tree-sitter/tree-sitte
                 [42]   Miyani D, Huang Z, Lie D. BinPro: A tool for binary source code provenance. arXiv:1711.00830, 2017.
                 [43]   Jiang L, An JW, Huang HH, Tang QY, Nie S, Wu S, Zhang YQ. BinaryAI: Binary software composition analysis via intelligent binary
                     source code matching. In: Proc. of the 46th IEEE/ACM Int’l Conf. on Software Engineering. Lisbon: ACM, 2024. 224. [doi: 10.1145/
                     3597503.3639100]
                 [44]   OWASP. OWASP dependency-track. 2025. https://owasp.org/www-project-dependency-track
   139   140   141   142   143   144   145   146   147   148   149