BugAuditor: Detecting Bugs via Inconsistent Defensive Code Auditing
Miaoqian Lin, Kai Chen, Hao Chen
摘要
Modern software systems contain complex behaviors that are prone to bugs when handled incorrectly. Detecting such bugs requires reliable oracles, which are difficult to construct as they require project-specific knowledge. Prior studies mainly obtain oracles from comparable code deviations, documentation, or historical bugs. However, these sources are inherently limited, leaving many project-specific bugs undetected.
In this paper, we propose inconsistent defensive handling as a new bug oracle for LLM-driven bug auditing. Specifically, we observe that real-world systems contain abundant defensive code, where developers proactively apply defensive handling in security-sensitive contexts to prevent bugs, and inconsistencies in such handling can indicate bugs. To realize this idea, we design BugAuditor, a framework that performs bug auditing via inconsistent defensive handling. BugAuditor first locates defensive code snippets across the codebase. It then reasons about the code to infer its security intent and underlying defensive patterns, characterizing the associated security-sensitive behaviors and defensive handling. Finally, BugAuditor applies the inferred patterns to audit the codebase and reports inconsistent defensive handling of the same security-sensitive behaviors across different contexts.
We evaluate BugAuditor on the Linux kernel. The results show that BugAuditor effectively mines project-specific knowledge embedded in defensive code that existing methods miss. Using the inferred defensive patterns, BugAuditor detects 54 long-latent bugs, including resource leaks, information leaks, and invalid pointer dereferences. To date, 20 bugs have been confirmed and fixed in the latest version, and two have been assigned CVE identifiers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper28
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 被引用 388 次
- GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program AnalysisYuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu 等ICSE 2024 · 被引用 131 次
- APISan: Sanitizing API Usages through Semantic Cross-CheckingInsu Yun, Changwoo Min, Xujie Si, Yeongjin Jang 等USENIX Security 2016 · 被引用 107 次
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 被引用 97 次
- PeX: A Permission Check Analysis Framework for Linux KernelTong Zhang, Wenbo Shen, Dongyoon Lee, Changhee Jung 等USENIX Security 2019 · 被引用 77 次
相关 Paper
- SpecAuditor: Generating Audit Specifications for LLM-Driven Bug DetectionMiaoqian Lin, Hao ChenS&P 2026 · 被引用 3 次
- eBPF Misbehavior Detection: Fuzzing with a Specification-Based OracleTao Lyu, Kumar Kartikeya Dwivedi, Thomas Bourgeat, Mathias Payer 等SOSP 2025
- ProtocolGuard: Detecting Protocol Non-compliance Bugs via LLM-guided Static Analysis and Dynamic VerificationXiangpu Song, Longjia Pei, Jianliang Wu, Yingpei Zeng 等NDSS 2026 · 被引用 3 次
- Non-Distinguishable Inconsistencies as a Deterministic Oracle for Detecting Security BugsQingyang Zhou, Qiushi Wu, Dinghao Liu, Shouling Ji 等CCS 2022 · 被引用 2 次
- Detecting Missed Security Operations Through Differential Checking of Object-based Similar PathsDinghao Liu, Qiushi Wu, Shouling Ji, Kangjie Lu 等CCS 2021 · 被引用 11 次
