VulShield: Protecting Vulnerable Code Before Deploying Patches
Yuan Li, Chao Zhang, Jinhao Zhu, Penghui Li, Chenyang Li, Songtao Yang, Wende Tan
摘要
—Despite the high frequency of vulnerabilities exposed in software, patching these vulnerabilities remains slow and challenging, which leaves a potential attack window. To mitigate this threat, researchers seek temporary solutions to prevent vulnerabilities from being exploited or triggered before they are officially patched. However, prior approaches have limited protection scope, often require code modification of the target vulnerable programs, and rely on recent system features. These limitations significantly reduce their usability and practicality. In this work, we introduce VulShield, an automated temporary protection system that addresses these limitations. VulShield leverages sanitizer reports, and automatically generates security policies that describe the vulnerability triggering conditions. The policies are then enforced through a Linux kernel module that can efficiently detect and prevent vulnerability from being triggered or exploited at runtime. By carefully designing the kernel module, VulShield is capable of protecting both vulnerable kernels, and user-space programs running on them. It does not rely on recent system features like eBPF and Linux security modules. VulShield is also pluggable and non-invasive as it does not need to modify the code of target vulnerable software. We evaluated VulShield’s capability in a comprehensive set of vulnerabilities in 9 different types and found that VulShield mitigated all cases in an automated and effective manner. For Nginx, the latency introduced per request does not exceed 0.001 ms, while the peak performance overhead observed in UnixBench is 1.047%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- QuickSafe: Targeted Hardening Against Memory CorruptionJohannes Blaser, Floris Gorter, Klaus von Gleissenthall, Herbert BosS&P 2026
- Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy InjectionYihao Peng, Zizhen Zhu, Jiatian Hu, Jiaxu Wang 等USENIX Security 2026
它引用的顶会 Paper20
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- MarkUs: Drop-in use-after-free prevention for low-level languagesSam Ainsworth, Timothy M. JonesS&P 2020 · 被引用 63 次
- Adaptive Android Kernel Live PatchingYue Chen, Yulong Zhang, Zhi Wang, Liangzhao Xia 等USENIX Security 2017 · 被引用 60 次
- Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid ResponseZhen Huang, Mariana D'Angelo, Dhaval Miyani, David LieS&P 2016 · 被引用 59 次
- InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on AndroidYaohui Chen, Yuping Li, Long Lu, Yueh-Hsun Lin 等NDSS 2018 · 被引用 32 次
相关 Paper
- PET: Prevent Discovered Errors from Being Triggered in the Linux KernelZicheng Wang, Yueqi Chen, Qingkai ZengUSENIX Security 2023
- Automatic Hot Patch Generation for Android KernelsZhengzi Xu, Yulong Zhang, Longri Zheng, Liangzhao Xia 等USENIX Security 2020
- Sifter: protecting security-critical kernel modules in Android through attack surface reductionHsin-Wei Hung, Yingtong Liu, Ardalan Amiri SaniMobiCom 2022 · 被引用 6 次
- pPatch: Automated Vulnerability UnpatchingTianyi Jing, Pengyu Ding, Meng Xu, Yinhao Hu 等FSE 2026
- Precisely Characterizing Security Impact in a Flood of Patches via Symbolic Rule ComparisonQiushi Wu, Yang He, Stephen McCamant, Kangjie LuNDSS 2020
