{"id":"https://openalex.org/W4400121141","doi":"https://doi.org/10.1145/3634737.3657007","title":"VFCFinder: Pairing Security Advisories and Patches","display_name":"VFCFinder: Pairing Security Advisories and Patches","publication_year":2024,"publication_date":"2024-06-28","ids":{"openalex":"https://openalex.org/W4400121141","doi":"https://doi.org/10.1145/3634737.3657007"},"language":"en","primary_location":{"id":"doi:10.1145/3634737.3657007","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3634737.3657007","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5084967148","display_name":"Trevor Dunlap","orcid":"https://orcid.org/0000-0002-9055-4079"},"institutions":[{"id":"https://openalex.org/I137902535","display_name":"North Carolina State University","ror":"https://ror.org/04tj63d06","country_code":"US","type":"education","lineage":["https://openalex.org/I137902535"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Trevor Dunlap","raw_affiliation_strings":["North Carolina State University, Raleigh, North Carolina, United States of America"],"raw_orcid":"https://orcid.org/0000-0002-9055-4079","affiliations":[{"raw_affiliation_string":"North Carolina State University, Raleigh, North Carolina, United States of America","institution_ids":["https://openalex.org/I137902535"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054851330","display_name":"Elizabeth Lin","orcid":"https://orcid.org/0000-0001-8856-5062"},"institutions":[{"id":"https://openalex.org/I137902535","display_name":"North Carolina State University","ror":"https://ror.org/04tj63d06","country_code":"US","type":"education","lineage":["https://openalex.org/I137902535"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Elizabeth Lin","raw_affiliation_strings":["North Carolina State University, Raleigh, North Carolina, USA"],"raw_orcid":"https://orcid.org/0000-0001-8856-5062","affiliations":[{"raw_affiliation_string":"North Carolina State University, Raleigh, North Carolina, USA","institution_ids":["https://openalex.org/I137902535"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5024034310","display_name":"William Enck","orcid":"https://orcid.org/0000-0002-3043-8092"},"institutions":[{"id":"https://openalex.org/I137902535","display_name":"North Carolina State University","ror":"https://ror.org/04tj63d06","country_code":"US","type":"education","lineage":["https://openalex.org/I137902535"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"William Enck","raw_affiliation_strings":["North Carolina State University, Raleigh, North Carolina, United States of America"],"raw_orcid":"https://orcid.org/0000-0002-3043-8092","affiliations":[{"raw_affiliation_string":"North Carolina State University, Raleigh, North Carolina, United States of America","institution_ids":["https://openalex.org/I137902535"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5021122418","display_name":"Bradley Reaves","orcid":"https://orcid.org/0000-0001-7902-1821"},"institutions":[{"id":"https://openalex.org/I137902535","display_name":"North Carolina State University","ror":"https://ror.org/04tj63d06","country_code":"US","type":"education","lineage":["https://openalex.org/I137902535"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Bradley Reaves","raw_affiliation_strings":["North Carolina State University, Raleigh, North Carolina, United States of America"],"raw_orcid":"https://orcid.org/0000-0001-7902-1821","affiliations":[{"raw_affiliation_string":"North Carolina State University, Raleigh, North Carolina, United States of America","institution_ids":["https://openalex.org/I137902535"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5084967148"],"corresponding_institution_ids":["https://openalex.org/I137902535"],"apc_list":null,"apc_paid":null,"fwci":2.9481,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.91974981,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1128","last_page":"1142"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9966999888420105,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9966999888420105,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9952999949455261,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.995199978351593,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/pairing","display_name":"Pairing","score":0.739638090133667},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6816921830177307},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4032239615917206},{"id":"https://openalex.org/keywords/physics","display_name":"Physics","score":0.0705738365650177}],"concepts":[{"id":"https://openalex.org/C14103023","wikidata":"https://www.wikidata.org/wiki/Q11681459","display_name":"Pairing","level":3,"score":0.739638090133667},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6816921830177307},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4032239615917206},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0705738365650177},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C54101563","wikidata":"https://www.wikidata.org/wiki/Q124131","display_name":"Superconductivity","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3634737.3657007","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3634737.3657007","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1517093113","display_name":null,"funder_award_id":"CNS-2207008 CNS-1946273","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W2076118331","https://openalex.org/W2612690371","https://openalex.org/W2887030713","https://openalex.org/W2911997683","https://openalex.org/W2914851262","https://openalex.org/W2914874661","https://openalex.org/W2963518130","https://openalex.org/W2979826702","https://openalex.org/W3008088841","https://openalex.org/W3040158574","https://openalex.org/W3088691441","https://openalex.org/W3137480023","https://openalex.org/W3202579690","https://openalex.org/W3214263053","https://openalex.org/W4205596332","https://openalex.org/W4205637777","https://openalex.org/W4212967226","https://openalex.org/W4230313626","https://openalex.org/W4232648333","https://openalex.org/W4237498081","https://openalex.org/W4240783423","https://openalex.org/W4245744969","https://openalex.org/W4246907949","https://openalex.org/W4286331380","https://openalex.org/W4286539963","https://openalex.org/W4289976167","https://openalex.org/W4293153014","https://openalex.org/W4308643994","https://openalex.org/W4327949044","https://openalex.org/W4381304075","https://openalex.org/W4384347367","https://openalex.org/W4385525355","https://openalex.org/W4386336981"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W3015473028","https://openalex.org/W3201176751","https://openalex.org/W1993094293","https://openalex.org/W2029180842","https://openalex.org/W2024971119","https://openalex.org/W2057898405","https://openalex.org/W2953807518","https://openalex.org/W2258335979"],"abstract_inverted_index":{"Security":[0,124],"advisories":[1,149],"are":[2,26],"the":[3,47,72,76,84,122,130,137,170],"primary":[4],"channel":[5],"of":[6,22,51,105,129,147],"communication":[7],"for":[8,53,70,83],"discovered":[9],"vulnerabilities":[10],"in":[11,103,121],"open-source":[12,154],"software,":[13],"but":[14],"they":[15],"often":[16],"lack":[17],"crucial":[18],"information.":[19],"Specifically,":[20],"63%":[21],"vulnerability":[23,35,158],"database":[24,159],"reports":[25],"missing":[27,119],"their":[28],"patch":[29],"links,":[30],"also":[31],"referred":[32],"to":[33,90,115,142,150,161,168],"as":[34],"fixing":[36],"commits":[37],"(VFCs).":[38],"This":[39],"paper":[40],"introduces":[41],"VFCFinder,":[42],"a":[43,54,67,109,144],"tool":[44],"that":[45],"generates":[46],"top-five":[48],"ranked":[49,86],"set":[50],"VFCs":[52,120,131],"given":[55],"security":[56,148],"advisory":[57],"using":[58],"Natural":[59],"Language":[60,62],"Programming":[61],"(NL-PL)":[63],"models.":[64],"VFCFinder":[65,88,114],"achieves":[66],"96.6%":[68],"recall":[69,82],"finding":[71],"correct":[73],"VFC":[74],"within":[75],"Top-5":[77],"commits,":[78],"and":[79,95,134],"an":[80],"80.0%":[81],"Top-1":[85,106],"commit.":[87],"generalizes":[89],"nine":[91],"different":[92],"programming":[93],"languages":[94],"outperforms":[96],"state-of-the-art":[97],"approaches":[98],"by":[99],"36":[100],"percentage":[101],"points":[102],"terms":[104],"recall.":[107],"As":[108],"practical":[110,145],"contribution,":[111],"we":[112],"used":[113],"backfill":[116],"over":[117],"300":[118],"GitHub":[123],"Advisory":[125],"(GHSA)":[126],"database.":[127,139],"All":[128],"were":[132],"accepted":[133],"merged":[135],"into":[136],"GHSA":[138],"In":[140],"addition":[141],"demonstrating":[143],"pairing":[146],"VFCs,":[151],"our":[152],"general":[153],"implementation":[155],"will":[156],"allow":[157],"maintainers":[160],"drastically":[162],"improve":[163],"data":[164],"quality,":[165],"supporting":[166],"efforts":[167],"secure":[169],"software":[171],"supply":[172],"chain.":[173]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":1}],"updated_date":"2026-04-28T14:05:53.105641","created_date":"2025-10-10T00:00:00"}
