USENIX Security2022Top-tier venue
OS-Aware Vulnerability Prioritization via Differential Severity Analysis
Qiushi Wu, Yue Xiao, Xiaojing Liao, Kangjie Lu
Abstract
The Linux kernel is quickly evolving and extensively customized. This results in thousands of versions and derivatives. Unfortunately, the Linux kernel is quite vulnerable. Each year, thousands of bugs are reported, and hundreds of them are security-related bugs. Given the limited resources, the kernel maintainers have to prioritize patching the more severe vulnerabilities. In practice, Common Vulnerability Scoring System (CVSS) [1] has become the standard for characterizing vulnerability severity. However, a fundamental problem exists when CVSS meets Linux-it is used in a "one for all" manner. The severity of a Linux vulnerability is assessed for only the mainstream Linux, and all affected versions and derivatives will simply honor and reuse the CVSS score. Such an undistinguished CVSS usage results in underestimation or overestimation of severity, which further results in delayed and ignored patching or wastes of the precious resources. In this paper, we propose OS-aware vulnerability prioritization (namely DIFFCVSS), which employs differential severity analysis for vulnerabilities. Specifically, given a severityassessed vulnerability, as well as the mainstream version and a target version of Linux, DIFFCVSS employs multiple new techniques based on static program analysis and natural language processing to differentially identify whether the vulnerability manifests a higher or lower severity in the target version. A unique strength of this approach is that it transforms the challenging and laborious CVSS calculation into automatable differential analysis. We implement DIFFCVSS and apply it to the mainstream Linux and downstream Android systems. The evaluation and user-study results show that DIFFCVSS is able to precisely perform the differential severity analysis, and offers a precise and effective way to identify vulnerabilities that deserve a severity reevaluation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8f497fb1-c963-4e52-bcae-1b5dbac4ddd5Cited by top-tier papers11
- Exploring ChatGPT's Capabilities on Vulnerability ManagementPeiyu Liu, Junming Liu, Lirong Fu, Kangjie Lu et al.USENIX Security 2024 · 52 citations
- Vulnerability Intelligence Alignment via Masked Graph Attention NetworksYue Qin, Yue Xiao, Xiaojing LiaoCCS 2023 · 8 citations
- Interdisciplinary Approaches to Cybervulnerability Impact Assessment for Energy Critical InfrastructureAndrea Gallardo, Robert Erbes, Katya Le Blanc, Lujo Bauer et al.CHI 2024 · 7 citations
- One Bug, Hundreds Behind: LLMs for Large-Scale Bug DiscoveryQiushi Wu, Yue Xiao, Dhilung Kirat, Kevin Eykholt et al.ICML 2026 · 5 citations
- SYSYPHUZZ: the Pressure of More CoverageZezhong Ren, Han Zheng, Zhiyao Feng, Qinying Wang et al.NDSS 2026 · 1 citation
Builds on13
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin et al.CCS 2017 · 682 citations
- SemFuzz: Semantics-based Automatic Generation of Proof-of-Concept ExploitsWei You, Peiyuan Zong, Kai Chen, XiaoFeng Wang et al.CCS 2017 · 148 citations
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 142 citations
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 97 citations
- Revery: From Proof-of-Concept to ExploitableYan Wang, Chao Zhang, Xiaobo Xiang, Zixuan Zhao et al.CCS 2018 · 85 citations
Related papers
- Precisely Characterizing Security Impact in a Flood of Patches via Symbolic Rule ComparisonQiushi Wu, Yang He, Stephen McCamant, Kangjie LuNDSS 2020
- Progressive Scrutiny: Incremental Detection of UBI bugs in the Linux KernelYizhuo Zhai, Yu Hao, Zheng Zhang, Weiteng Chen et al.NDSS 2022
- Shedding Light on CVSS Scoring Inconsistencies: A User-Centric Study on Evaluating Widespread Security VulnerabilitiesJulia Wunder, Andreas Kurtz, Christian Eichenmüller, Freya Gassmann et al.S&P 2024 · 25 citations
- What Do They Fix? LLM-Aided Categorization of Security Patches for Critical Memory BugsXingyu Li, Juefei Pu, Yifan Wu, Xiaochen Zou et al.NDSS 2026 · 2 citations
- Automated Detection of Configuration-Specific Security Vulnerabilities via Patch AnalysisFelipe de Sant'Anna Paixão, Joanna C. S. Santos, Paulo Anselmo da Mota Silveira Neto, Daniel Sadoc Menasché et al.FSE 2026
