Package managers such as NPM, Maven, and PyPI play a pivotal role in open-source software (OSS) ecosystems, streamlining the distribution and management of various freely available packages. The fine-grained details within software packages can unveil potential risks within existing OSS ecosystems, offering valuable insights for detecting malicious packages. In this study, we undertake a large-scale empirical analysis focusing on fine-grained information (FGI): the metadata, static, and dynamic functions. Specifically, we investigate the FGI usage across a diverse set of 50,000+ legitimate and 1,000+ malicious packages. Based on this diverse data collection, we conducted a comparative analysis between legitimate and malicious packages. Our findings reveal that (1) malicious packages have less metadata content and utilize fewer static and dynamic functions than legitimate ones; (2) malicious packages demonstrate a higher tendency to invoke HTTP/URL functions as opposed to other application services, such as FTP or SMTP; (3) FGI serves as a distinguishable indicator between legitimate and malicious packages; and (4) one dimension in FGI has sufficient distinguishable capability to detect malicious packages, and combining all dimensions in FGI cannot significantly improve overall performance.
翻译:包管理器(如NPM、Maven和PyPI)在开源软件生态系统中发挥着核心作用,它们简化了各种自由可用软件包的分发与管理。软件包内部的细粒度细节能够揭示现有开源生态系统中的潜在风险,为检测恶意包提供宝贵见解。在本研究中,我们开展了一项大规模实证分析,重点关注细粒度信息:元数据、静态功能和动态功能。具体而言,我们探究了50000多个合法包和1000多个恶意包中细粒度信息的使用情况。基于这一多样化的数据收集,我们对合法包与恶意包进行了比较分析。研究发现:(1)恶意包的元数据内容较少,并且使用的静态和动态功能少于合法包;(2)与FTP或SMTP等其他应用服务相比,恶意包更倾向于调用HTTP/URL功能;(3)细粒度信息可作为区分合法包与恶意包的有效指标;(4)细粒度信息中的单一维度具备足够的能力来检测恶意包,而组合所有维度并不能显著提升整体性能。