{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T06:03:54Z","timestamp":1778220234072,"version":"3.51.4"},"reference-count":33,"publisher":"Wiley","issue":"6","license":[{"start":{"date-parts":[[2015,6,5]],"date-time":"2015-06-05T00:00:00Z","timestamp":1433462400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Concurrency and Computation"],"published-print":{"date-parts":[[2016,4,25]]},"abstract":"<jats:title>Summary<\/jats:title><jats:p>Software vulnerability has long been considered an important threat to the system safety. A vulnerability is often reproduced because of the frequent code reuse by programmers. Security patches are usually not propagated to all code clones; however, they could be leveraged to discover unknown vulnerabilities. Static code auditing approaches are frequently proposed to scan source codes for security flaws; unfortunately, these approaches generate too many false positives. While dynamic execution analysis methods can precisely report vulnerabilities, they are ineffective in path exploration, which limits them to scale to large programs. With the purpose of detecting vulnerability in a scalable way with more preciseness, in this paper, we propose a novel mechanism, called software vulnerability discovery using Code Clone Verification (CLORIFI), that scalably discovers vulnerabilities in real world programs using code clone verification. In the beginning, we use a fast and scalable syntax\u2010based way to find code clones in program source codes based on released security patches. Subsequently, code clones are being verified using concolic testing to dramatically decrease the false positives. In addition, we mitigate the path explosion problem by backward sensitive data tracing in concolic execution. Experiments have been conducted with real\u2010world open\u2010source projects (recent Linux OS distributions and program packages). As a result, we found 7 real vulnerabilities out of 63 code clones from Ubuntu 14.04 LTS (Canonical, London, UK) and 10 vulnerabilities out of 40 code clones from CentOS 7.0 (The CentOS Project(community contributed)). Furthermore, we confirmed more code clone vulnerabilities in various versions of programs including Rsyslog (Open Source(Original author: Rainer Gerhards)), Apache (Apache Software Foundation, Forest Hill, Maryland, USA) and Firefox (Mozilla Corporation, Mountain View, California, USA). In order to evaluate the effectiveness of vulnerability verification in a systematic way, we also utilized Juliet Test Suite as measurement objects. The results show that CLORIFI achieves 98% accuracy with 0 false positives. Copyright \u00a9 2015 John Wiley &amp; Sons, Ltd.<\/jats:p>","DOI":"10.1002\/cpe.3532","type":"journal-article","created":{"date-parts":[[2015,6,6]],"date-time":"2015-06-06T03:32:57Z","timestamp":1433561577000},"page":"1900-1917","source":"Crossref","is-referenced-by-count":29,"title":["CLORIFI: software vulnerability discovery using code clone verification"],"prefix":"10.1002","volume":"28","author":[{"given":"Hongzhe","family":"Li","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering Korea University Seoul Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hyuckmin","family":"Kwon","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering Korea University Seoul Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonghoon","family":"Kwon","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering Korea University Seoul Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Heejo","family":"Lee","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering Korea University Seoul Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2015,6,5]]},"reference":[{"key":"e_1_2_7_2_1","doi-asserted-by":"crossref","unstructured":"HLi HKwon JKwon HLee.A scalable approach for vulnerability discovery based on security patches.Proceedings of 5th International Conference on Applications and Techniques in Information Security Melbourne Australia 2014;109\u2013122.","DOI":"10.1007\/978-3-662-45670-5_11"},{"key":"e_1_2_7_3_1","unstructured":"DWheeler Flawfinder.2011. (Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.dwheeler.com\/flawfinder) [Accessed on 27 April 2014]."},{"key":"e_1_2_7_4_1","doi-asserted-by":"crossref","unstructured":"DEvans Splint. Improving Security Using Extensible Lightweight Static Analysis.2002. (Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.splint.org) [Accessed on 20 April 2014].","DOI":"10.1109\/52.976940"},{"key":"e_1_2_7_5_1","doi-asserted-by":"crossref","unstructured":"FYamaguchi CWressnegger HGascon KRieck.Chucky: exposing missing checks in source code for vulnerability discovery.Proceedings of ACM SIGSAC Conference on Computer & Communications Security Berlin Germany 2013;499\u2013510.","DOI":"10.1145\/2508859.2516665"},{"key":"e_1_2_7_6_1","doi-asserted-by":"crossref","unstructured":"JViega JTBloch YKohno GMcGraw.ITS4: a static vulnerability scanner for C and C++ code.Proceedings of the Annual Computer Security Applications Conference(ACSAC) New Orleans Louisiana USA 2000;257\u2013267.","DOI":"10.1109\/ACSAC.2000.898880"},{"key":"e_1_2_7_7_1","doi-asserted-by":"crossref","unstructured":"KSen DMarinov GAgha.Cute: a concolic unit testing engine for C.Proceedings of ACM SIGSOFT International Symposium on Foundations of Software Engineering Lisbon Portugal;2005;263\u2013272.","DOI":"10.1145\/1095430.1081750"},{"key":"e_1_2_7_8_1","unstructured":"EHaugh MBishop.Testing C programs for buffer overflow vulnerabilities. Network and Distributed System Security Symposium San Diego California USA 2003;123\u2013130."},{"key":"e_1_2_7_9_1","unstructured":"HGhosh TOConnor GMcGraw.An automated approach for identifying potential vulnerabilities in software.Proceedings of the IEEE Symposium on Security and Privacy Oakland California USA 1998;104\u2013114."},{"key":"e_1_2_7_10_1","doi-asserted-by":"crossref","unstructured":"KMa KPhang JFoster MHicks.Directed symbolic execution.Proceedings of 18th International Conference on Static Analysis Berlin Heidelberg;2011;95\u2013111.","DOI":"10.1007\/978-3-642-23702-7_11"},{"key":"e_1_2_7_11_1","unstructured":"CCadar DDunbar DEngler.Klee: Unassisted and automatic generation of high\u2010coverage tests for complex systems programs.Proceedings of USENIX Symposium on Operating Systems Design and Implementation Vol.8 2008;209\u2013224."},{"key":"e_1_2_7_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00165-011-0200-9"},{"key":"e_1_2_7_13_1","doi-asserted-by":"crossref","unstructured":"MKim YKim YJang.Industrial application of concolic testing on embedded software: case studies.Proceedings of the IEEE International Conference on Software Testing Verification and Validation Montreal Canada 2012;390\u2013399.","DOI":"10.1109\/ICST.2012.119"},{"key":"e_1_2_7_14_1","doi-asserted-by":"crossref","unstructured":"JBurnim KSen.Heuristics for scalable dynamic test generation.Proceedings of IEEE\/ACM International Conference on Automated Software Engineering L'Aquila Italy 2008;443\u2013446.","DOI":"10.1109\/ASE.2008.69"},{"key":"e_1_2_7_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2012.345"},{"key":"e_1_2_7_16_1","doi-asserted-by":"crossref","unstructured":"MGabel JYang YYu MGoldszmidt ZSu.Scalable and systematic detection of buggy inconsistencies in source code. Proceedings of ACM International Conference on Object Oriented Programming Systems Languages and Applications Portland OR USA 2011;175\u2013190.","DOI":"10.1145\/1869459.1869475"},{"key":"e_1_2_7_17_1","doi-asserted-by":"crossref","unstructured":"LJiang GMisherghi ZSu SGlondu.Deckard: scalable and accurate tree\u2010based detection of code clones. Proceedings of International Conference on Software Engineering Minneapolis Minnesota USA 2007;96\u2013105.","DOI":"10.1109\/ICSE.2007.30"},{"key":"e_1_2_7_18_1","doi-asserted-by":"crossref","unstructured":"MSUddin CKRoy KASchneider AHindle.On the effectiveness of Simhash for detecting near\u2010miss clones in large scale software systems.Proceedings of the 18th Working Conference on Reverse Engineering Lero Limerick Ireland 2011;13\u201322.","DOI":"10.1109\/WCRE.2011.12"},{"key":"e_1_2_7_19_1","doi-asserted-by":"crossref","unstructured":"JJang AAgrawal DBrumley.ReDeBug: finding unpatched code clones in entire os distributions.Proceedings of IEEE Symposium on Security and Privacy San Francisco California USA 2012;48\u201362.","DOI":"10.1109\/SP.2012.13"},{"key":"e_1_2_7_20_1","unstructured":"RHastings BJoyce.Purify: fast detection of memory leaks and access errors.Proceedings of the Winter USENIX Conference San Francisco California USA 1992;125\u2013136."},{"key":"e_1_2_7_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.55"},{"key":"e_1_2_7_22_1","unstructured":"DZhang DLiu YLei DKung CCsallner WWang.Detecting vulnerabilities in C programs using trace\u2010based testing.Proceedings of IEEE\/IFIP International Conference on Dependable Systems and Networks Chicago Illinois USA 2010;241\u2013250."},{"key":"e_1_2_7_23_1","doi-asserted-by":"crossref","unstructured":"HSeo SKim.How we get there: A context\u2010guided search strategy in concolic testing.Proceeding (FSE 2014) Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering ACM:New York NY USA 2014 413\u2013424.","DOI":"10.1145\/2635868.2635872"},{"key":"e_1_2_7_24_1","doi-asserted-by":"crossref","unstructured":"PGarg FIvancic GBalakrishnan NMaeda AGupta.Feedback\u2010directed unit test generation for C\/C++ using concolic execution.Proceedings of the 2013 International Conference on Software San Francisco California USA 2013;132\u2013141.","DOI":"10.1109\/ICSE.2013.6606559"},{"key":"e_1_2_7_25_1","doi-asserted-by":"crossref","unstructured":"YLi ZSu LWang XLi.Steering symbolic execution to less traveled paths.Proceedings of ACM SIGPLAN International Conference on Object Oriented Programming Systems Languages & Applications Indianapolis Indiana USA 2013;19\u201332.","DOI":"10.1145\/2509136.2509553"},{"key":"e_1_2_7_26_1","doi-asserted-by":"crossref","unstructured":"RMajumdar KSen.Hybrid concolic testing.Proceedings of ICSE International Conference on Software Engineering Minneapolis Minnesota USA 2007;416\u2013426.","DOI":"10.1109\/ICSE.2007.41"},{"key":"e_1_2_7_27_1","doi-asserted-by":"publisher","DOI":"10.1080\/15427951.2004.10129096"},{"key":"e_1_2_7_28_1","first-page":"2615","article-title":"Hash kernels for structured data","volume":"10","author":"Shi Q","year":"2011","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_2_7_29_1","doi-asserted-by":"crossref","unstructured":"PGodefroid NKlarlund KSen.Dart: directed automated random testing.Proceedings of ACM Sigplan Conference on Programming Language Design and Implementation Chicago IL USA 2005;213\u2013223.","DOI":"10.1145\/1064978.1065036"},{"key":"e_1_2_7_30_1","doi-asserted-by":"crossref","unstructured":"HLi TKim MBat\u2010Erdene HLee.Software vulnerability detection using backward trace analysis and symbolic execution.Proceedings of International Conference on Availability Reliability and Security Regensburg Germany 2013;446\u2013454.","DOI":"10.1109\/ARES.2013.59"},{"key":"e_1_2_7_31_1","doi-asserted-by":"crossref","unstructured":"LMoura d NBjorner.Z3:An efficient SMT solver.Proceedings of 14th International Conference on Tools and Algorithms for the Construction and Analysis of Systems Budapest Hungary 2008;337\u2013340.","DOI":"10.1007\/978-3-540-78800-3_24"},{"key":"e_1_2_7_32_1","unstructured":"2000. (Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/www.cs.hmc.edu\/~geoff\/classes\/hmc.cs070.200101\/homework10\/hashfuncs.html) [Accessed 8 August 2014]."},{"key":"e_1_2_7_33_1","unstructured":"CVulnerabilities.Exposures cve. (Available from:https:\/\/2.zoppoz.workers.dev:443\/http\/cve.mitre.org.)"},{"key":"e_1_2_7_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1327452.1327492"}],"container-title":["Concurrency and Computation: Practice and Experience"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fcpe.3532","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/cpe.3532","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T11:27:32Z","timestamp":1748431652000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/10.1002\/cpe.3532"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,6,5]]},"references-count":33,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2016,4,25]]}},"alternative-id":["10.1002\/cpe.3532"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/cpe.3532","archive":["Portico"],"relation":{},"ISSN":["1532-0626","1532-0634"],"issn-type":[{"value":"1532-0626","type":"print"},{"value":"1532-0634","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,6,5]]}}}