Kintsugi: Empowering LLMs to Mitigate Web Vulnerabilities via Runtime Policy Injection
Yihao Peng, Zizhen Zhu, Jiatian Hu, Jiaxu Wang, Hai Wan, Xibin Zhao
摘要
The "response gap" between vulnerability detection and patching leaves web applications exposed to high-impact exploits such as remote code execution, command injection, and server-side request forgery. Current mitigations are flawed: code fixes often break functionality, while global runtime policies produce excessive false positives. We propose Kintsugi, an automated runtime containment system that provides temporary protection for exploits that manifest as diverging syscall behaviors at the OS level. Kintsugi uses a three-stage pipeline: First, by performing differential syscall analysis on normal and malicious requests, it locates a few vulnerability-related functions. Subsequently, leveraging LLMs, it precisely delineates the boundaries of the specific code snippets causing the malicious behavior within these functions and establishes policy trigger points. Finally, by analyzing the execution profiles from normal requests, it derives a deterministic, least-privilege syscall whitelist to serve as the runtime policy. This policy is enforced at the kernel level via eBPF and cgroups and is dynamically activated only when the request's execution flow enters the protected code snippet. Evaluation on 27 real-world CVEs across PHP, Python, and Java shows that Kintsugi effectively neutralizes diverse exploits and their variants while preserving original application functionality. Kintsugi achieves an average response time of 7.6 minutes. While the enforcement of surgical policies introduces a modest average latency overhead of 9.2% on targeted APIs, the impact on concurrent non-vulnerable traffic remains minimal, with an average throughput (RPS) drop of only 2.21%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper27
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Automated Repair of Programs from Large Language ModelsZhiyu Fan, Xiang Gao, Martin Mirchev, Abhik Roychoudhury 等ICSE 2023 · 被引用 213 次
- VulRepair: a T5-based automated software vulnerability repairMichael Fu, Chakkrit Tantithamthavorn, Trung Le, Van Nguyen 等FSE 2022 · 被引用 206 次
- Combating Dependence Explosion in Forensic Analysis Using Alternative Tag Propagation SemanticsMd Nahid Hossain, Sanaz Sheikhi, R. SekarS&P 2020 · 被引用 179 次
相关 Paper
- VulShield: Protecting Vulnerable Code Before Deploying PatchesYuan Li, Chao Zhang, Jinhao Zhu, Penghui Li 等NDSS 2025
- Kintsugi: Secure Hotpatching for Code-Shadowing Real-Time Embedded SystemsPhilipp Mackensen, Christian Niesler, Roberto Blanco, Lucas Davi 等USENIX Security 2025
- Talos: Neutralizing Vulnerabilities with Security Workarounds for Rapid ResponseZhen Huang, Mariana D'Angelo, Dhaval Miyani, David LieS&P 2016 · 被引用 59 次
- Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall SequencesHugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang, Suryadipta Majumdar 等NDSS 2024
- Web Application Vulnerability Repair Via Context-Aware Fault Localization and Directed Differential FuzzingChenlin Wang, Wei MengS&P 2026
