Athena: Vulnerability-Affected Library Identification via Knowledge Graph Completion
Athena uses knowledge-graph completion to fix the widespread problem of missing or wrong affected-library data in vulnerability databases—a root cause of SCA blind spots.
Summary written by editorial AI · Source link below
arXiv:2609.01187v1 Announce Type: cross Abstract: A single vulnerability in a widely used library can cascade through millions of dependent applications, yet more than half of vulnerability database entries contain missing or incorrect affected-library information. Existing automated approaches neglect the relational structure of vulnerability databases, treating identification as an isolated text retrieval problem. In this paper, we propose Athena, the first graph-based approach for vulnerabil
Editorial Analysis
Inaccurate affected-library metadata in CVE databases causes SCA tools to miss real exposures; automated graph-based correction could close a systemic gap in supply-chain security.
Audit your vulnerability management pipeline for reliance on potentially incomplete NVD affected-library data and consider enrichment via alternative sources.
Over half of vulnerability database entries misidentify affected libraries, creating hidden exposure in every enterprise relying on automated dependency scanning.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the DevSecOps Desk
- Boundary-Mutation Testing for Pattern-Based Secret Detection: A Rule-Level Method and Cross-Scanner Evaluation4d
- PatchBench: Evaluating AI Agents for Vulnerability Patching4d
- Coder's registry infrastructure compromised to push malicious modules4d
- Modelstamp: Pre-Deserialization Verification of Machine-Learning Artifacts and Runtime Environment State5d
- Barriers to Using Static Application Security Testing (SAST) Tools: A Literature Review5d