Using Safety Properties to Generate Vulnerability Patches
Zhen Huang, David Lie, Gang Tan, Trent Jaeger
Abstract
Security vulnerabilities are among the most critical software defects in existence. When identified, programmers aim to produce patches that prevent the vulnerability as quickly as possible, motivating the need for automatic program repair (APR) methods to generate patches automatically. Unfortunately, most current APR methods fall short because they approximate the properties necessary to prevent the vulnerability using examples. Approximations result in patches that either do not fix the vulnerability comprehensively, or may even introduce new bugs. Instead, we propose property-based APR, which uses human-specified, program-independent and vulnerability-specific safety properties to derive source code patches for security vulnerabilities. Unlike properties that are approximated by observing the execution of test cases, such safety properties are precise and complete. The primary challenge lies in mapping such safety properties into source code patches that can be instantiated into an existing program. To address these challenges, we propose Senx, which, given a set of safety properties and a single input that triggers the vulnerability, detects the safety property violated by the vulnerability input and generates a corresponding patch that enforces the safety property and thus, removes the vulnerability. Senx solves several challenges with property-based APR: it identifies the program expressions and variables that must be evaluated to check safety properties and identifies the program scopes where they can be evaluated, it generates new code to selectively compute the values it needs if calling existing program code would cause unwanted side effects, and it uses a novel access range analysis technique to avoid placing patches inside loops where it could incur performance overhead. Our evaluation shows that the patches generated by Senx successfully fix 32 of 42 real-world vulnerabilities from 11 applications including various tools or libraries for manipulating graphics/media files, a programming language interpreter, a relational database engine, a collection of programming tools for creating and managing binary programs, and a collection of basic file, shell, and text manipulation tools.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 33038148-bb74-40ac-b6af-33df33213abeCited by top-tier papers31
- How Effective Are Neural Networks for Fixing Security VulnerabilitiesYi Wu, Nan Jiang, Hung Viet Pham, Thibaud Lutellier et al.ISSTA 2023 · 86 citations
- PDiff: Semantic-based Patch Presence Testing for Downstream KernelsZheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen et al.CCS 2020 · 54 citations
- Concolic program repairRidwan Salihin Shariffdeen, Yannic Noller, Lars Grunske, Abhik RoychoudhuryPLDI 2021 · 45 citations
- SPIDER: Enabling Fast Patch Propagation In Related Software RepositoriesAravind Machiry, Nilo Redini, Eric Camellini, Christopher Kruegel et al.S&P 2020 · 39 citations
- FlexOS: towards flexible OS isolationHugo Lefeuvre, Vlad-Andrei Badoiu, Alexander Jung, Stefan Lucian Teodorescu et al.ASPLOS 2022 · 36 citations
Builds on1
Related papers
- Program vulnerability repair via inductive inferenceYuntong Zhang, Xiang Gao, Gregory J. Duck, Abhik RoychoudhuryISSTA 2022 · 29 citations
- VGX: Large-Scale Sample Generation for Boosting Learning-Based Software Vulnerability AnalysesYu Nong, Richard Fang, Guangbei Yi, Kunsong Zhao et al.ICSE 2024 · 23 citations
- PROPR: Property-Based Automatic Program RepairMatthías Páll Gissurarson, Leonhard Applis, Annibale Panichella, Arie van Deursen et al.ICSE 2022 · 13 citations
- Trust Enhancement Issues in Program RepairYannic Noller, Ridwan Shariffdeen, Xiang Gao, Abhik RoychoudhuryICSE 2022 · 51 citations
- Towards Boosting Patch Execution On-the-FlySamuel Benton, Yuntong Xie, Lan Lu, Mengshi Zhang et al.ICSE 2022 · 10 citations
