Susheng Wu

dblp:315/5866 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2025
0009-0005-2169-7032ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 2 first-author · 6 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 ProfMal: Detecting Malicious NPM Packages by the Synergy between Static and Dynamic Analysis
abstract
Open source software (OSS) has become the foundation of modern applications, but its transitive dependencies make it especially vulnerable to supply chain attacks. One common tactic is to inject malicious code into third-party packages. NPM, in particular, due to its widespread use and large volume of packages, has become the popular target of malicious code injection. While various detectors have been proposed, they suffer three limitations, i.e., inadequate behavior modeling of obfuscated code, ignoring object-centric features of JavaScript, and lack of synergy between static and dynamic analysis. These limitations lead to imprecise modeling of program behavior and hinder detection effectiveness.To address these limitations, we propose ProfMal to identify malicious NPM packages, which leverages the synergy between static and dynamic analysis to construct behavior graphs for each package. Specifically, our static analysis constructs the behavior graphs through object-sensitive analysis, while identifying sensitive API calls and locating statically unresolved calls. Our dynamic analysis augments the behavior graphs by resolving those statically unresolved calls. Based on these comprehensive behavior graphs, we train a graph-based classifier to identify maliciousness. Our evaluation has indicated that ProfMal achieves the highest F1-score of 92.4%, outperforming the state-of-the-arts by 6.2% to 48.8%. During a three-month real-world detection, ProfMal has detected 496 previously unknown malicious NPM packages, and all of them have been confirmed and removed from NPM.
Susheng Wu, Bihuan Chen 0001, You Lu 0005, Zhuotong Zhou, Yiheng Cao, Xin Peng 0001
ASE3
2024 Identifying Affected Libraries and Their Ecosystems for Open Source Software Vulnerabilities
abstract
Software composition analysis (SCA) tools have been widely adopted to identify vulnerable libraries used in software applications. Such SCA tools depend on a vulnerability database to know affected libraries of each vulnerability. However, it is labor-intensive and error prone for a security team to manually maintain the vulnerability database. While several approaches adopt extreme multi-label learning to predict affected libraries for vulnerabilities, they are practically ineffective due to the limited library labels and the unawareness of ecosystems.
Susheng Wu, Wenyan Song, Kaifeng Huang 0001, Bihuan Chen 0001, Xin Peng 0001
ICSE1
2024 SpiderScan: Practical Detection of Malicious NPM Packages Based on Graph-Based Behavior Modeling and Matching
abstract
Open source software (OSS) supply chains have been attractive targets for attacks. One of the significant, popular attacks is realized by malicious packages on package registries. NPM, as the largest package registry, has been recently flooded with malicious packages. In response to this severe security risk, many detection tools have been proposed. However, these tools do not model malicious behavior in a holistic way; only consider a predefined set of sensitive APIs; and require huge manual confirmation effort due to high false positives and binary detection results. Thus, their practical usefulness is hindered.
Ruisi Wang, Zhuotong Zhou, Susheng Wu, Shulin Ke, Bihuan Chen 0001, Xin Peng 0001
ASE5
2024 Vision: Identifying Affected Library Versions for Open Source Software Vulnerabilities
abstract
Vulnerability reports play a crucial role in mitigating open-source software risks. Typically, the vulnerability report contains affected versions of a software. However, despite the validation by security expert who discovers and vendors who review, the affected versions are not always accurate. Especially, the complexity of maintaining its accuracy increases significantly when dealing with multiple versions and their differences. Several advances have been made to identify affected versions. However, they still face limitations. First, some existing approaches identify affected versions based on repository-hosting platforms (i.e., GitHub), but these versions are not always consistent with those in package registries (i.e., Maven). Second, existing approaches fail to distinguish the importance of different vulnerable methods and patched statements in face of vulnerabilities with multiple methods and change hunks.
Susheng Wu, Ruisi Wang, Kaifeng Huang 0001, Yiheng Cao, Wenyan Song, Zhuotong Zhou, Bihuan Chen 0001, Xin Peng 0001
ASE1
2024 Magneto: A Step-Wise Approach to Exploit Vulnerabilities in Dependent Libraries via LLM-Empowered Directed Fuzzing
abstract
The wide adoption of open source third-party libraries can propagate vulnerabilities that originally exist in third-party libraries through dependency chains to downstream projects. To mitigate this security risk, vulnerability exploitation analysis has been proposed to further reduce false positives of vulnerability reachability analysis. However, existing approaches work less effectively when the vulnerable function of the vulnerable library is indirectly invoked by a client project through a call chain of multiple steps.
Zhuotong Zhou, Yongzhuo Yang, Susheng Wu, Bihuan Chen 0001, Xin Peng 0001
ASE3
2023 Demystifying Dependency Bugs in Deep Learning Stack
abstract
Deep learning (DL) applications, built upon a heterogeneous and complex DL stack (e.g., Nvidia GPU, Linux, CUDA driver, Python runtime, and TensorFlow), are subject to software and hardware dependencies across the DL stack. One challenge in dependency management across the entire engineering lifecycle is posed by the asynchronous and radical evolution and the complex version constraints among dependencies. Developers may introduce dependency bugs (DBs) in selecting, using and maintaining dependencies. However, the characteristics of DBs in DL stack is still under-investigated, hindering practical solutions to dependency management in DL stack. To bridge this gap, this paper presents the first comprehensive study to characterize symptoms, root causes and fix patterns of DBs across the whole DL stack with 446 DBs collected from StackOverflow posts and GitHub issues. For each DB, we first investigate the symptom as well as the lifecycle stage and dependency where the symptom is exposed. Then, we analyze the root cause as well as the lifecycle stage and dependency where the root cause is introduced. Finally, we explore the fix pattern and the knowledge sources that are used to fix it. Our findings from this study shed light on practical implications on dependency management.
Kaifeng Huang 0001, Bihuan Chen 0001, Susheng Wu, Junming Cao, Lei Ma 0003, Xin Peng 0001
ESEC/SIGSOFT FSE3
2021 DeepVuler: A Vulnerability Intelligence Mining System for Open-Source Communities
abstract
Open-source code repositories play an important role in software development, but they also introduce a slew of security issues. Firstly, everyone can use open-source projects and libraries from the third-party ecosystem, which increases the risk of vulnerabilities attacking. Secondly, it may cause a domino effect and make these products inherit these vulnerabilities when referring to vulnerable repositories. Traditional technical methods were unable to detect these public flaws in a timely manner, leaving these developers in an insecure situation. Although vulnerability management institutes like CVE and NVD provide inadequate coverage, leading to a lack of timely, reliable, and detailed information about open-source projects' vulnerabilities. To better detect and repair vulnerability, we designed a vulnerability intelligence mining system named DeepVuler based on threads analysis and changed code in open-source communities using machine learning. We choose and define a series of effective features extracted from open-source communities to early infer vulnerability intelligence. Our result shows that two proposed models of DeepVuler achieve a detection rate of 0.979 in threads and 0.890 in changed codes. Besides, the detection from DeepVuler is often days or weeks ahead of official vulnerability disclosure.
Susheng Wu, Mingxu Sun, Renyu Duan, Cheng Huang 0003
TrustCom1