01 / GRANULARITY
Declarations overstate the scope
A dependency may select a fixed version. Even when a vulnerable version is present, its code may never be imported or its vulnerable functions called.
Vulnerability Propagation Scoring System
How far does one vulnerability travel? VPSS moves from declared dependencies to function calls, traces propagation across an ecosystem, and measures impact through breadth, depth, and snapshots in time.
CALL-GRAPH ANALYSIS / JAVA MAVEN / DYNAMIC 0–10 SCORE
Real vulnerabilities evaluated
Projects in the graph, approx.
Maven releases, approx.
Supply-chain impact depends on the versions selected, the code actually used, and the dependencies downstream software retains over time.
01 / GRANULARITY
A dependency may select a fixed version. Even when a vulnerable version is present, its code may never be imported or its vulnerable functions called.
02 / SCALE
Building a call graph for every release is expensive. A project-level graph narrows the search, then hierarchical pruning reserves fine analysis for the remaining candidates.
03 / TIME
Severity and propagation impact are different dimensions. Patch adoption, retained dependencies, and ecosystem growth change the snapshot that VPSS measures.
Prune candidates and watch a worklist handle joins and cycles in small examples. Then explore the score using recorded snapshot data. The browser runs no live Maven analysis.
HIERARCHICAL PRUNING / SIX DOWNSTREAM CANDIDATES
← Scroll inside the graph · Select a node to inspect evidence →
Retained means passing the current filter, not proven exploitability. This example has one release per project; the paper tracks projects (P) and releases (PV) separately.
WORKLIST / REVISIT ONLY WHEN STATE CHANGES
← Scroll inside the graph to inspect joins and cycles →
A separate four-project example uses finite target-function sets to demonstrate joins and cycles. Its counts are independent of the preceding six-candidate graph.
IMPACT EXPLORER / RECORDED SNAPSHOT INPUTS
Start from a recorded CVE-2016-5393 snapshot, then adjust the inputs to explore how breadth and depth affect the score. Edits create a hypothetical scenario. Release counts stay at least as large as project counts, and average depth cannot exceed maximum depth.
Vulnerability intelligence, fixing patches, and dependency metadata become affected projects and releases, propagation paths, and a VPSS score for a chosen snapshot.
I / HIERARCHICAL WORKLIST ANALYSIS
A project-level dependency graph discovers candidates. Patches generate vulnerable-function candidates; an LLM filters irrelevant modifications and gives reasons for manual verification. Version, import, and call-graph pruning refine the scope, while a worklist tracks new state to a fixed point.
Static call graphs and version intelligence have accuracy limits. Reflection, dynamic loading, and incomplete patches can affect results. Call reachability is not successful exploitation. Sources: §III, §VI-A.
II / GRAPH-AWARE DYNAMIC SCORING
Breadth combines affected shares of direct and transitive projects and releases, then applies logarithmic scaling. Depth combines maximum and average path length. Their product is mapped to 0–10 by an exponential function.
Empirically chosen weights and scaling parameters affect score sensitivity. Time evolution reflects changing snapshots and need not decline monotonically. Sources: §III-E, §V-C, §VI-C.
Ecosystem-wide evaluation of 100 real Maven vulnerabilities. Select a stage to inspect average direct and transitive candidate counts. These are historical measurements from Figure 6.
Source: §V-B / Figure 6
MCR index snapshot: 2024-12-26
Pruning ratios describe scope reduction, not precision or recall.
Each vulnerability was analyzed independently from scratch. Times range from 1.2 seconds to 54 hours under the paper’s dataset and setup.
Linear scale / each row normalized to its own initial value / P and PV tracked separately
The paper did not measure initial maximum or average path lengths because of the cost. Path statistics at v1, v2, and v3 compare already-pruned graphs.
Inspect Figure 6 and the setup ↗CASE STUDY / CVE-2016-5393
A vulnerability in Hadoop Common directly affects 228 projects at t₀ and reaches another 154 transitively. The paper reports a maximum path length of 7 across Hadoop and Hive components. Across 24 observations, VPSS declines slowly from 7.35 to 6.86. Affected release counts grow, while ecosystem growth reduces their relative share.
Sources: §V-D / Figure 8 and repository vpss_stats records
t₀ is NVD disclosure; t₂₃ is 23 intervals of 30 days later (690 days). Every point is a recorded sample; lines only connect samples.
40th IEEE/ACM International Conference on Automated Software Engineering · ASE 2025 · pp. 65–77
@inproceedings{ruan2025vpss,
title={Propagation-Based Vulnerability Impact Assessment for Software Supply Chains},
author={Ruan, Bonan and Lin, Zhiwei and Liu, Jiahao and Zhang, Chuqi and Ji, Kaihang and Liang, Zhenkai},
booktitle={Proceedings of the 40th IEEE/ACM International Conference on Automated Software Engineering},
pages={65--77},
year={2025},
doi={10.1109/ASE63991.2025.00014}
}