| 講演抄録/キーワード |
| 講演名 |
2025-03-06 16:20
GPLライセンスOSSのソースコード分析によるルータにおける脆弱性修正の調査 ○木原百々香・佐々木貴之(横浜国大)・秋山満昭(NTT)・吉岡克成(横浜国大) ICSS2024-87 |
| 抄録 |
(和) |
ルータで利用されるOSSの脆弱性修正手法には,OSSコンポーネントのバージョンアップによる修正と,パッチ適用による修正がある.前者については,SCAツールを用いた解析により,ルータメーカがどの程度実施しているかが評価されている.一方,後者については,バージョンを変更せずパッチが適用されることがあり,SCAツールのようなバージョンに基づいた脆弱性検出手法では調査が困難である.本研究では,ルータで使用されるGPLライセンスのOSSソースコードを,メーカへの開示請求や,メーカのOSSソースコード公開サイトから入手し,ソースコードとOSSコミュニティによるパッチを比較することで,パッチによる脆弱性修正の有無を調査した.その結果,SCAツールで脆弱性ありと判定されたOSSの中で,パッチによる修正事例や,脆弱な関数の削除事例を確認した. |
| (英) |
There are two primary methods for fixing vulnerabilities in OSS used in routers: upgrading OSS components to newer versions and applying security patches. The former has been extensively analyzed using Software Composition Analysis (SCA) tools, revealing how frequently router manufacturers implement version upgrades. In contrast, investigating the latter is more difficult because patches are sometimes applied without changing the version, making it hard for version-based detection methods like SCA tools to identify such fixes. In this study, we obtained the source code of GPL-licensed OSS used in routers through disclosure requests to manufacturers and from manufacturers' OSS source code distribution sites. We then compared the disclosed source code with security patches provided by OSS communities to determine whether patches were applied to fix vulnerabilities. As a result, we identified cases where vulnerabilities reported by SCA tools were actually fixed through patches or by removing vulnerable functions. |
| キーワード |
(和) |
GPL / 脆弱性修正 / ルータ / / / / / |
| (英) |
GPL / Vulnerability fixes / Router / / / / / |
| 文献情報 |
信学技報, vol. 124, no. 422, ICSS2024-87, pp. 136-143, 2025年3月. |
| 資料番号 |
ICSS2024-87 |
| 発行日 |
2025-02-27 (ICSS) |
| ISSN |
Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
| PDFダウンロード |
ICSS2024-87 |