Improving Accuracy of OWASP Dependency-Check Through Optimized CPE Matching to Reduce False Positives and False Negatives
DOI:
https://doi.org/10.55549/epstem.1443Keywords:
Software composition analysis, Dependency-check, Open-source security, CPE matching, Vulnerability detection, Software engineeringAbstract
In today’s digital era, the use of open-source dependencies in modern software development has become commonplace. However, this practice increases security risks due to vulnerabilities hidden within the open-source components being used. Software Composition Analysis (SCA) is one of the approaches that can be utilized to detect and mitigate the risks arising from the use of open-source dependencies. Nevertheless, existing SCA tools still face a fundamental challenge in the form of false positives (reported vulnerabilities that are not actually relevant) and false negatives (vulnerabilities that remain undetected), which can degrade the accuracy of detection results and hinder security analysis as well as mitigation decisions. This study focuses on improving the accuracy of one widely used SCA tool, OWASP Dependency-Check, by highlighting one of its main sources of error: the Common Platform Enumeration (CPE) matching process between project dependencies and vulnerability entries in the Common Vulnerabilities and Exposures (CVE) database. The objectives of this research are to analyze CPE matching error patterns, design optimization mechanisms to improve the matching process, and evaluate the impact of these optimizations.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 The Eurasia Proceedings of Science, Technology, Engineering and Mathematics

This work is licensed under a Creative Commons Attribution 4.0 International License.


