Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid Response
Zhen Huang, Mariana D'Angelo, Dhaval Miyani, David Lie
Abstract
There is often a considerable delay between the discovery of a vulnerability and the issue of a patch. One way to mitigate this window of vulnerability is to use a configuration workaround, which prevents the vulnerable code from being executed at the cost of some lost functionality -- but only if one is available. Since application configurations are not specifically designed to mitigate software vulnerabilities, we find that they only cover 25.2% of vulnerabilities. To minimize patch delay vulnerabilities and address the limitations of configuration workarounds, we propose Security Workarounds for Rapid Response (SWRRs), which are designed to neutralize security vulnerabilities in a timely, secure, and unobtrusive manner. Similar to configuration workarounds, SWRRs neutralize vulnerabilities by preventing vulnerable code from being executed at the cost of some lost functionality. However, the key difference is that SWRRs use existing error-handling code within applications, which enables them to be mechanically inserted with minimal knowledge of the application and minimal developer effort. This allows SWRRs to achieve high coverage while still being fast and easy to deploy. We have designed and implemented Talos, a system that mechanically instruments SWRRs into a given application, and evaluate it on five popular Linux server applications. We run exploits against 11 real-world software vulnerabilities and show that SWRRs neutralize the vulnerabilities in all cases. Quantitative measurements on 320 SWRRs indicate that SWRRs instrumented by Talos can neutralize 75.1% of all potential vulnerabilities and incur a loss of functionality similar to configuration workarounds in 71.3% of those cases. Our overall conclusion is that automatically generated SWRRs can safely mitigate 2.1× more vulnerabilities, while only incurring a loss of functionality comparable to that of traditional configuration workarounds.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0d0486e3-1845-478d-b486-7c8b01d3ba12Cited by top-tier papers18
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Using Safety Properties to Generate Vulnerability PatchesZhen Huang, David Lie, Gang Tan, Trent JaegerS&P 2019 · 91 citations
- Adaptive Android Kernel Live PatchingYue Chen, Yulong Zhang, Zhi Wang, Liangzhao Xia et al.USENIX Security 2017 · 60 citations
- PDiff: Semantic-based Patch Presence Testing for Downstream KernelsZheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen et al.CCS 2020 · 54 citations
- V-SZZ: Automatic Identification of Version Ranges Affected by CVE VulnerabilitiesLingfeng Bao, Xin Xia, Ahmed E. Hassan, Xiaohu YangICSE 2022 · 45 citations
Related papers
- Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy InjectionYihao Peng, Zizhen Zhu, Jiatian Hu, Jiaxu Wang et al.USENIX Security 2026
- VulShield: Protecting Vulnerable Code Before Deploying PatchesYuan Li, Chao Zhang, Jinhao Zhu, Penghui Li et al.NDSS 2025
- DiagConfig: Configuration Diagnosis of Performance Violations in Configurable Software SystemsZhiming Chen, Pengfei Chen, Peipei Wang, Guangba Yu et al.FSE 2023 · 9 citations
- PET: Prevent Discovered Errors from Being Triggered in the Linux KernelZicheng Wang, Yueqi Chen, Qingkai ZengUSENIX Security 2023
- Vision: Identifying Affected Library Versions for Open Source Software VulnerabilitiesSusheng Wu, Ruisi Wang, Kaifeng Huang, Yiheng Cao et al.ASE 2024 · 1 citation
