Exploiting Library Vulnerability via Migration Based Automating Test Generation
Zirui Chen, Xing Hu, Xin Xia, Yi Gao, Tongtong Xu, David Lo, Xiaohu Yang
摘要
In software development, developers extensively utilize third-party libraries to avoid implementing existing functionalities. When a new third-party library vulnerability is disclosed, project maintainers need to determine whether their projects are affected by the vulnerability, which requires developers to invest substantial effort in assessment. However, existing tools face a series of issues: static analysis tools produce false alarms, dynamic analysis tools require existing tests and test generation tools have low success rates when facing complex vulnerabilities. Vulnerability exploits, as code snippets provided for reproducing vulnerabilities after disclosure, contain a wealth of vulnerabilityrelated information. This study proposes a new method based on vulnerability exploits, called Vesta (Vulnerability Exploit-based Software Testing Auto-Generator), which provides vulnerability exploit tests as the basis for developers to decide whether to update dependencies. Vesta extends the search-based test generation methods by adding a migration step, ensuring the similarity between the generated test and the vulnerability exploit, which increases the likelihood of detecting potential library vulnerabilities in a project. We perform experiments on 30 vulnerabilities disclosed in the past five years, involving 60 vulnerability-project pairs, and compare the experimental results with the baseline method, Transfer. The success rate of Vesta is 71.7% which is a 53.4% improvement over Transfer in the effectiveness of verifying exploitable vulnerabilities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Learning from the Past: Real-World Exploit Migration for Smart Contract PoC GenerationKairan Sun, Zhengzi Xu, Kaixuan Li, Lyuye Zhang 等ASE 2025 · 被引用 3 次
- Propagation-Based Vulnerability Impact Assessment for Software Supply ChainsBonan Ruan, Zhiwei Lin, Jiahao Liu, Chuqi Zhang 等ASE 2025 · 被引用 2 次
- Diffploit: Facilitating Cross-Version Exploit Migration for Open Source Library VulnerabilitiesZirui Chen, Zhipeng Xue, Jiayuan Zhou, Xing Hu 等ICSE 2026
- Depradar: Agentic Coordination for Context-Aware Defect Impact Analysis in Deep Learning LibrariesYi Gao, Xing Hu, Tongtong Xu, Jiali Zhao 等ICSE 2026
- Actionable Warning Is Not Enough: Recommending Valid Actionable Warnings with Weak SupervisionZhipeng Xue, Zhipeng Gao, Tongtong Xu, Xing Hu 等ICSE 2026
它引用的顶会 Paper5
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu 等ICSE 2021 · 被引用 85 次
- Your Exploit is Mine: Automatic Shellcode Transplant for Remote ExploitsTiffany Bao, Ruoyu Wang, Yan Shoshitaishvili, David BrumleyS&P 2017 · 被引用 56 次
- Modular call graph construction for security scanning of Node.js applicationsBenjamin Barslev Nielsen, Martin Toldam Torp, Anders MøllerISSTA 2021 · 被引用 47 次
- Test mimicry to assess the exploitability of library vulnerabilitiesHong Jin Kang, Truong Giang Nguyen, Bach Le, Corina S. Pasareanu 等ISSTA 2022 · 被引用 22 次
- VulDeePecker: A Deep Learning-Based System for Vulnerability DetectionZhen Li, Deqing Zou, Shouhuai Xu, Xinyu Ou 等NDSS 2018
相关 Paper
- Magneto: A Step-Wise Approach to Exploit Vulnerabilities in Dependent Libraries via LLM-Empowered Directed FuzzingZhuotong Zhou, Yongzhuo Yang, Susheng Wu, Yiheng Huang 等ASE 2024 · 被引用 7 次
- NAVEX: Precise and Scalable Exploit Generation for Dynamic Web ApplicationsAbeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. VenkatakrishnanUSENIX Security 2018 · 被引用 85 次
- Determining the Unreachable: Constraint-Guided Reachability Analysis for Dependency VulnerabilitiesWenbu Feng, Xiaohong Li, Ruitao Feng, Yao Zhang 等OOPSLA 2026 · 被引用 1 次
- Locating the Security Patches for Disclosed OSS Vulnerabilities with Vulnerability-Commit Correlation RankingXin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao 等CCS 2021 · 被引用 43 次
- Compatible Remediation on Vulnerabilities from Third-Party Libraries for Java ProjectsLyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen 等ICSE 2023 · 被引用 19 次
