Analyzing Code Commits Addressing Vulnerabilities in the Android Project

Authors

  • Marcelino Barros Universidade Federal do Agreste de Pernambuco (UFAPE) https://orcid.org/0009-0005-8109-2756
    Competing Interests

    None.

  • Gustavo Torres Universidade Federal do Agreste de Pernambuco (UFAPE)
    Competing Interests

    None.

  • Rodrigo Andrade Universidade Federal do Agreste de Pernambuco (UFAPE) https://orcid.org/0000-0001-9051-5347

DOI:

https://doi.org/10.22456/2175-2745.149849

Keywords:

Software Vulnerabilities, Android Project, Vulnerability Fixing Commits, CVE

Abstract

Software vulnerabilities are a significant concern, posing high costs and risks to developers and users. While previous work has focused on automated detection and vulnerability datasets, a deeper understanding of the human element in the fixing process is needed. Our research aims to characterize how developers address software vulnerabilities in the Android project. We conducted an empirical study using vulnerability-fixing commits from the Big-Vul dataset to analyze fix complexity, developer experience, and the delay in public disclosure. Our findings indicate that vulnerability fixes are typically small, affecting fewer lines of code and files compared to regular commits. Furthermore, our results suggest that the authors of these fixes are predominantly experienced in the codebase, though contributions from inexperienced developers also occur. Finally, we observe a considerable delay between a vulnerability fix being published and its corresponding CVE being publicly updated. These conclusions contribute to a better understanding of vulnerability remediation and can assist developers in assigning responsibilities and estimating fix times.

Downloads

Download data is not yet available.

References

[1] BOSU, A. et al. Identifying the characteristics of vulnerable code changes: An empirical study. In: ACM SIGSOFT International Symposium on the Foundations of Software Engineering. New York, NY, USA: Association for Computing Machinery, 2014. p. 257–268.

[2] MENEELY, A. et al. When a patch goes bad: Exploring the properties of vulnerability-contributing commits. In: International Symposium on Empirical Software Engineering and Measurement. [S.l.]: IEEE, 2013. p. 65–74.

[3] KRSUAL, I. V. Software Vulnerability Analysis. Tese (Doutorado) — Purdue University, 1998.

[4] ALLEN, J. et al. Software Security Engineering. [S.l.]: Addison-Wesley Professional, 2006.

[5] PONTA, S. E. et al. A manually-curated dataset of fixes to vulnerabilities of open-source software. In: International Conference on Mining Software Repositories. [S.l.]: IEEE, 2019. p. 383–387.

[6] PERL, H. et al. Vccfinder: Finding potential vulnerabilities in open-source projects to assist code audits. In: ACM SIGSAC Conference on Computer and Communications Security (CCS). New York, NY, USA: Association for Computing Machinery, 2015. p. 426–437.

[7] GRAF, J.; HECKER, M.; MOHR, M. Using joana for information flow control in java programs - a practical guide. In: Software Engineering 2013 - Workshopband. [S.l.]: Gesellschaft für Informatik e.V., 2013. p. 123–138.

[8] WAN, L. Automated vulnerability detection system based on commit messages. Tese (Doutorado) — Nanyang Technological University, 2019.

[9] FAN, J. et al. A c/c++ code vulnerability dataset with code changes and cve summaries. In: International Conference on Mining Software Repositories. New York, NY, USA: Association for Computing Machinery, 2020. p. 508–512.

[10] GKORTZIS, A.; MITROPOULOS, D.; SPINELLIS, D. Vulinoss: A dataset of security vulnerabilities in open-source systems. In: International Conference on Mining Software Repositories. New York, NY, USA: Association for Computing Machinery, 2018. p. 18–21.

[11] The MITRE Corporation. Common Vulnerabilities and Exposures (CVE). 2024. ⟨https://cve.mitre.org⟩.

[12] PIANTADOSI, V.; SCALABRINO, S.; OLIVETO, R. Fixing of security vulnerabilities in open source projects: A case study of apache http server and apache tomcat. In: Conference on Software Testing, Validation and Verification. [S.l.]: IEEE, 2019. p. 68–78.

[13] GOOGLE. GitHub Android Project. 2025. ⟨https://github.com/android/⟩.

[14] MENEELY, A. et al. An empirical investigation of socio-technical code review metrics and security vulnerabilities. In: Proceedings of the 6th International Workshop on Social Software Engineering. [S.l.: s.n.], 2014. p. 37–44.

[15] STRAUB, B.; CHACON, S. Pro git. [S.l.]: Springer Nature, 2014.

[16] KALLIAMVAKOU, E. et al. The promises and perils of mining github. In: Proceedings of the 11th Working Conference on Mining Software Repositories. New York, NY, USA: Association for Computing Machinery, 2014. (MSR 2014). p. 92–101. ISBN 9781450328630. Disponível em: ⟨https://doi.org/10.1145/2597073.2597074⟩.

[17] National Institute of Standards and Technology. National Vulnerability Database (NVD). 2024. ⟨https://nvd.nist.gov/⟩.

[18] HALFOND, W. G.; VIEGAS, J.; ORSO, A. A classification of sql injection attacks and countermeasures. In: Proceedings of the IEEE International Symposium on Secure Software Engineering (ISSSE). [S.l.: s.n.], 2006.

[19] GUPTA, S.; GUPTA, B. B. Cross-site scripting (xss) attacks and defense mechanisms: classification and state-of-the-art. International Journal of System Assurance Engineering and Management, Springer, v. 8, p. 512–530, 2017.

[20] COWAN, C. et al. PointGuard™: Protecting Pointers from Buffer Overflow Vulnerabilities. In: USENIX Security Symposium (USENIX Security). [S.l.: s.n.], 2003.

[21] BARTH, A.; JACKSON, C.; MITCHELL, J. C. Robust defenses for cross-site request forgery. In: ACM Conference on Computer and Communications Security. [S.l.: s.n.], 2008. p. 75–88.

[22] DRAKONAKIS, K.; IOANNIDIS, S.; POLAKIS, J. The cookie hunter: Automated black-box auditing for web authentication and authorization flaws. In: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security. [S.l.: s.n.], 2020. p. 1953–1970.

[23] CHEN, Y. et al. Diversevul: A new vulnerable source code dataset for deep learning based vulnerability detection. In: International Symposium on Research in Attacks, Intrusions and Defenses. [S.l.: s.n.], 2023. p. 654–668.

[24] BHANDARI, G.; NASEER, A.; MOONEN, L. CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software. In: International Conference on Predictive Models and Data Analytics in Software Engineering. [S.l.]: ACM, 2021. p. 10.

[25] WOOD, A. D.; STANKOVIC, J. A. Denial of service in sensor networks. Computer, IEEE, v. 35, n. 10, p. 54–62, 2002.

[26] BASILI, V.; CALDIERA, G.; ROMBACH, D. H. The goal question metric approach. In: MARCINIAK, J. J. (Ed.). Encyclopedia of Software Engineering. New Jersey: Wiley, 1994. p. 528–532.

[27] MUNSON, J. C.; ELBAUM, S. G. Code churn: a measure for estimating the impact of code change. In: International Conference on Software Maintenance. [S.l.]: IEEE, 1998. p. 24–31.

[28] NAGAPPAN, N.; BALL, T. Use of relative code churn measures to predict system defect density. In: International Conference on Software Engineering. St. Louis, MO, USA: IEEE, 2005. p. 284–292.

[29] BALACHANDRAN, V. Reducing human effort and improving quality in peer code reviews using automatic static analysis and reviewer recommendation. In: International Conference on Software Engineering. San Francisco, CA, USA: IEEE Press, 2013. p. 931–940.

[30] BACCHELLI, A.; BIRD, C. Expectations, outcomes, and challenges of modern code review. In: International Conference on Software Engineering. San Francisco, CA, USA: IEEE Press, 2013. p. 712–721.

[31] ABLESON, F.; KING, C.; ORTIZ, C. E. Android in action. [S.l.]: Simon and Schuster, 2011.

[32] Online Appendix. Analyzing Code Commits Addressing Vulnerabilities in the Android Project. 2025. ⟨https://zenodo.org/records/16944853⟩.

[33] NEUHÄUSER, M. Wilcoxon-mann-whitney test. In: International encyclopedia of statistical science. [S.l.]: Springer, 2025. p. 2896–2898.

[34] HOUSEHOLDER, A. D. et al. The cert guide to coordinated vulnerability disclosure. [S.l.], 2017.

[35] WOHLIN, C. et al. Experimentation in software engineering. [S.l.]: Springer Science & Business Media, 2012.

[36] MENEELY, A.; WILLIAMS, O. Interactive churn metrics: Socio-technical variants of code churn. SIGSOFT Softw. Eng. Notes, Association for Computing Machinery, New York, NY, USA, v. 37, n. 6, p. 1–6, nov. 2012. ISSN 0163-5948. Disponível em: ⟨https://doi.org/10.1145/2382756.2382785⟩.

[37] APACHE. Apache HTTP Server Project. 2025. ⟨https://httpd.apache.org/⟩.

[38] PIANTADOSI, V.; SCALABRINO, S.; OLIVETO, R. Fixing of security vulnerabilities in open source projects: A case study of apache http server and apache tomcat. In: 2019 12th IEEE Conference on Software Testing, Validation and Verification (ICST). [S.l.]: IEEE, 2019. p. 68–78.

[39] BOSU, A. Characteristics of the vulnerable code changes identified through peer code review. In: Companion Proceedings of the 36th International Conference on Software Engineering. New York, NY, USA: Association for Computing Machinery, 2014. (ICSE Companion 2014). p. 736–738. ISBN 9781450327688. Disponível em: ⟨https://doi.org/10.1145/2591062.2591200⟩.

[40] PERL, H. et al. Vccfinder: Finding potential vulnerabilities in open-source projects to assist code audits. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. New York, NY, USA: Association for Computing Machinery, 2015. (CCS ’15). p. 426–437. ISBN 9781450338325. Disponível em: ⟨https://doi.org/10.1145/2810103.2813604⟩.

Downloads

Published

2026-01-30

How to Cite

Barros, M., Torres, G., & Andrade, R. (2026). Analyzing Code Commits Addressing Vulnerabilities in the Android Project. Revista De Informática Teórica E Aplicada, 33(1), 122–134. https://doi.org/10.22456/2175-2745.149849

Issue

Section

Regular Papers
Received 2025-08-28
Accepted 2025-12-26
Published 2026-01-30

Similar Articles

1 2 3 4 5 > >> 

You may also start an advanced similarity search for this article.