A Survey of Third-Party Library Security Research in Application Software
Jia Zeng, Dan Han, Yaling Zhu, Yangzhong Wang, Fangchen Weng

TL;DR
This survey reviews existing research on third-party library security in application software, highlighting detection, ecosystem understanding, and defense strategies to mitigate associated vulnerabilities and threats.
Contribution
It comprehensively summarizes current research achievements and future directions in third-party library security, aiding developers and researchers in improving software safety.
Findings
Third-party libraries pose significant security risks.
Detection tools assist in identifying third-party libraries.
Fortification defenses are crucial for mitigating vulnerabilities.
Abstract
In the current software development environment, third-party libraries play a crucial role. They provide developers with rich functionality and convenient solutions, speeding up the pace and efficiency of software development. However, with the widespread use of third-party libraries, associated security risks and potential vulnerabilities are increasingly apparent. Malicious attackers can exploit these vulnerabilities to infiltrate systems, execute unauthorized operations, or steal sensitive information, posing a severe threat to software security. Research on third-party libraries in software becomes paramount to address this growing security challenge. Numerous research findings exist regarding third-party libraries' usage, ecosystem, detection, and fortification defenses. Understanding the usage and ecosystem of third-party libraries helps developers comprehend the potential risks…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security
