USENIX Security2026Top-tier venue
Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy Injection
Yihao Peng, Zizhen Zhu, Jiatian Hu, Jiaxu Wang, Hai Wan, Xibin Zhao
Abstract
The "response gap" between vulnerability detection and patching leaves web applications exposed to high-impact exploits such as remote code execution, command injection, and server-side request forgery. Current mitigations are flawed: code fixes often break functionality, while global runtime policies produce excessive false positives. We propose Kintsugi, an automated runtime containment system that provides temporary protection for exploits that manifest as diverging syscall behaviors at the OS level. Kintsugi uses a three-stage pipeline: First, by performing differential syscall analysis on normal and malicious requests, it locates a few vulnerability-related functions. Subsequently, leveraging LLMs, it precisely delineates the boundaries of the specific code snippets causing the malicious behavior within these functions and establishes policy trigger points. Finally, by analyzing the execution profiles from normal requests, it derives a deterministic, least-privilege syscall whitelist to serve as the runtime policy. This policy is enforced at the kernel level via eBPF and cgroups and is dynamically activated only when the request's execution flow enters the protected code snippet. Evaluation on 27 real-world CVEs across PHP, Python, and Java shows that Kintsugi effectively neutralizes diverse exploits and their variants while preserving original application functionality. Kintsugi achieves an average response time of 7.6 minutes. While the enforcement of surgical policies introduces a modest average latency overhead of 9.2% on targeted APIs, the impact on concurrent non-vulnerable traffic remains minimal, with an average throughput (RPS) drop of only 2.21%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 52e56418-baad-4fc0-82ca-bd497330a13bBuilds on27
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 273 citations
- Automated Repair of Programs from Large Language ModelsZhiyu Fan, Xiang Gao, Martin Mirchev, Abhik Roychoudhury et al.ICSE 2023 · 213 citations
- VulRepair: a T5-based automated software vulnerability repairMichael Fu, Chakkrit Tantithamthavorn, Trung Le, Van Nguyen et al.FSE 2022 · 206 citations
- Combating Dependence Explosion in Forensic Analysis Using Alternative Tag Propagation SemanticsMd Nahid Hossain, Sanaz Sheikhi, R. SekarS&P 2020 · 179 citations
Related papers
- VulShield: Protecting Vulnerable Code Before Deploying PatchesYuan Li, Chao Zhang, Jinhao Zhu, Penghui Li et al.NDSS 2025
- Kintsugi: Secure Hotpatching for Code-Shadowing Real-Time Embedded SystemsPhilipp Mackensen, Christian Niesler, Roberto Blanco, Lucas Davi et al.USENIX Security 2025
- Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid ResponseZhen Huang, Mariana D'Angelo, Dhaval Miyani, David LieS&P 2016 · 59 citations
- Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall SequencesHugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang, Suryadipta Majumdar et al.NDSS 2024
- Web Application Vulnerability Repair Via Context-Aware Fault Localization and Directed Differential FuzzingChenlin Wang, Wei MengS&P 2026
