Page 55 - 《软件学报》2026年第7期
P. 55

2740                                                       软件学报  2026  年第  37  卷第  7  期


                    (3) 提升可扩展性, 与编译工具链集成. 现有工具在分析大型                 Python-C/C++软件包时存在显著的可扩展性问
                 题, 部分工具依赖动态输入、特定项目结构或繁杂的源汇点配置, 难以适应真实工程环境. 基于                           GCC、LLVM/Clang
                 等编译工具链的技术表现出较好的可扩展性, 是比较可取的设计方向.

                 References
                  [1]   Alfadel M, Costa DE, Shihab E. Empirical analysis of security vulnerabilities in Python packages. Empirical Software Engineering, 2023,
                     28(3): 59. [doi: 10.1007/s10664-022-10278-4]
                  [2]   Guo WB, Xu ZZ, Liu CW, Huang C, Fang Y, Liu Y. An empirical study of malicious code in PyPI ecosystem. In: Proc. of the 38th Int’l
                     Conf. on Automated Software Engineering. Luxembourg: IEEE, 2023. 166–177. [doi: 10.1109/ASE56229.2023.00135]
                  [3]   Samaana H, Costa DE, Shihab E, Abdellatif A. A machine learning-based approach for detecting malicious PyPI packages. In: Proc. of
                     the 40th ACM/SIGAPP Symp. on Applied Computing. Catania: ACM, 2025. 1617–1626. [doi: 10.1145/3672608.3707756]
                  [4]   Sun XB, Gao XG, Cao SC, Bo LL, Wu XX, Huang KF. 1+1>2: Integrating deep code behaviors with metadata features for malicious
                     PyPI package detection. In: Proc. of the 39th IEEE/ACM Int’l Conf. on Automated Software Engineering. Sacramento: ACM, 2024.
                     1159–1170. [doi: 10.1145/3691620.3695493]
                  [5]   Vu DL, Pashchenko I, Massacci F, Plate H, Sabetta A. Typosquatting and combosquatting attacks on the Python ecosystem. In: Proc. of
                     the 2020 European Symp. on Security and Privacy Workshops. Genoa: IEEE, 2020. 509–514. [doi: 10.1109/EuroSPW51379.2020.00074]
                  [6]   Grichi M, Abidi M, Jaafar F, Eghan EE, Adams B. On the impact of interlanguage dependencies in multilanguage systems empirical case
                     study on Java Native Interface applications (JNI). IEEE Trans. on Reliability, 2021, 70(1): 428–440. [doi: 10.1109/TR.2020.3024873]
                  [7]   Li W, Li L, Cai HP. On the vulnerability proneness of multilingual code. In: Proc. of the 30th ACM Joint European Software Engineering
                     Conf. and Symp. on the Foundations of Software Engineering. Singapore: ACM, 2022. 847–859. [doi: 10.1145/3540250.3549173]
                  [8]   Tan G, Croft J. An empirical security study of the native code in the JDK. In: Proc. of the 17th USENIX Security Symp. San Jose:
                     USENIX Association, 2008. 365–378.
                  [9]   Hu MZ, Zhang Y. An empirical study of the Python/C API on evolution and bug patterns. Journal of Software: Evolution and Process,
                     2023, 35(2): e2507. [doi: 10.1002/smr.2507]
                 [10]   Hu MZ, Zhang Y. The Python/C API: Evolution, usage statistics, and bug patterns. In: Proc. of the 27th Int’l Conf. on Software Analysis,
                     Evolution and Reengineering. London: IEEE, 2020. 532–536. [doi: 10.1109/SANER48275.2020.9054835]
                 [11]   Li SL, Tan G. Finding reference-counting errors in Python/C programs with affine analysis. In: Proc. of the 28th European Conf. on
                     Object-oriented Programming. Uppsala: Springer, 2014. 80–104. [doi: 10.1007/978-3-662-44202-9_4]
                 [12]   Mao JJ, Chen Y, Xiao QX, Shi YC. RID: Finding reference count bugs with inconsistent path pair checking. In: Proc. of the 21st Int’l
                     Conf.  on  Architectural  Support  for  Programming  Languages  and  Operating  Systems.  Atlanta:  ACM,  2016.  531–544.  [doi:  10.1145/
                     2872362.2872389]
                 [13]   Ma XT, Yan JW, Zhang H, Yan J, Zhang J. Detecting memory errors in Python native code by tracking object lifecycle with reference
                     count.  In:  Proc.  of  the  38th  Int’l  Conf.  on  Automated  Software  Engineering.  Luxembourg:  IEEE,  2023.  1429–1440.  [doi:  10.1109/
                     ASE56229.2023.00198]
                 [14]   Li W, Ming J, Luo XP, Cai HP. PolyCruise: A cross-language dynamic information flow analysis. In: Proc. of the 31st USENIX Security
                     Symp. Boston: USENIX Association, 2022. 2513–2530.
                 [15]   Li W, Ruan JY, Yi GB, Cheng L, Luo XP, Cai HP. PolyFuzz: Holistic greybox fuzzing of multi-language systems. In: Proc. of the 32nd
                     USENIX Security Symp. Anaheim: USENIX Association, 2023. 1379–1396.
                 [16]   Monat R, Ouadjaout A, Miné A. A multilanguage static analysis of Python programs with native C extensions. In: Proc. of the 28th Int’l
                     Symp. on Static Analysis. Chicago: Springer, 2021. 323–345. [doi: 10.1007/978-3-030-88806-0_16]
                 [17]   Hu MZ, Zhang Y, Huang WC, Xiong Y. Static type inference for foreign functions of Python. In: Proc. of the 32nd Int’l Symp. on
                     Software Reliability Engineering. Wuhan: IEEE, 2021. 423–433. [doi: 10.1109/ISSRE52982.2021.00051]
                 [18]   Hu MZ, Yu L, Zhang Y, Han LP. A survey of multilanguage interoperability and its program analysis. IEEE Trans. on Reliability, 2025,
                     74(4): 4944–4958. [doi: 10.1109/TR.2025.3576267]
                 [19]   Simons AJH. Borrow, copy or steal? Loans and larceny in the orthodox canonical form. In: Proc. of the 13th ACM SIGPLAN Int’l Conf.
                     on Object-oriented Programming Systems, Languages, and Applications. Vancouver: ACM, 1998. 65–83. [doi: 10.1145/286936.286948]
                 [20]   Kirchner  F,  Kosmatov  N,  Prevosto  V,  Signoles  J,  Yakobowski  B.  Frama-C:  A  software  analysis  perspective.  Formal  Aspects  of
                     Computing, 2015, 27(3): 573–609. [doi: 10.1007/s00165-014-0326-7]
                 [21]   Zhang J, Zhang C, Xuan JF, Xiong YF, Wang QX, Liang B, Li L, Dou WS, Chen ZB, Chen LQ, Cai Y. Recent progress in program
   50   51   52   53   54   55   56   57   58   59   60