Mingxi Feng

dblp:360/7629 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 50% Malware analysis · 50%
Software engineering, system software, and programming languages
1 paper
Program analysis · 62% Software maintenance and evolution · 38%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Malware analysis
malware detection
0.712023
MalWuKong: Towards Fast, Accurate, and Multilingual Detection of Malicious Code Poisoning in OSS Supply Chains · ASE 2023
Systems and software security
software supply chain security
0.712023
MalWuKong: Towards Fast, Accurate, and Multilingual Detection of Malicious Code Poisoning in OSS Supply Chains · ASE 2023
Program analysis › static analysis
interprocedural analysis
0.712023
MalWuKong: Towards Fast, Accurate, and Multilingual Detection of Malicious Code Poisoning in OSS Supply Chains · ASE 2023
Software maintenance and evolution › software ecosystems
package repositories
0.212023
MalWuKong: Towards Fast, Accurate, and Multilingual Detection of Malicious Code Poisoning in OSS Supply Chains · ASE 2023
Software maintenance and evolution
software ecosystems
0.212023
MalWuKong: Towards Fast, Accurate, and Multilingual Detection of Malicious Code Poisoning in OSS Supply Chains · ASE 2023

Methods — techniques the papers use, named apart from their topics

source code slicing · 1.3interprocedural analysis · 0.7inter-procedural analysis · 0.7
YearPublicationVenuePosition
2023 MalWuKong: Towards Fast, Accurate, and Multilingual Detection of Malicious Code Poisoning in OSS Supply Chains
abstract
In the face of increased threats within software registries and management systems, we address the critical need for effective malicious code detection. In this paper, we propose an innovative approach that integrates source code slicing, inter-procedural analysis, and cross-file inter-procedural analysis, thereby enhancing the detection precision and reducing false positives. This approach has been encapsulated within a multi-analysis-based framework for automatic detection of malicious code in real-world software packages. In its application to major third-party software registries like PyPI and NPM, our framework has proven effective, identifying 130 malicious packages from a total of 169,640 monitored over a continuous period of five weeks. This work advances the current state-of-the-art solution to malicious code detection, demonstrating significant practical impact in strengthening the software supply chain defense.
Ningke Li, Shenao Wang 0001, Mingxi Feng, Kailong Wang 0001, Meizhen Wang, Haoyu Wang 0001
ASE3