Web Application Vulnerability Repair Via Context-Aware Fault Localization and Directed Differential Fuzzing
Chenlin Wang, Wei Meng
摘要
Web applications handle sensitive data, yet exploitation of their vulnerabilities can cause significant losses due to their widespread use. While vulnerability detection techniques have become increasingly sophisticated, timely remediation remains challenging due to substantial manual effort requirements. Automated vulnerability repair has become increasingly mature, yet research targeting web applications remains limited due to challenges posed by dynamic languages like PHP, which powers 73.1 % of websites. Leveraging existing LLM-based repair work is non-trivial as these systems rely on specialized toolchains and readily available test suites that web applications rarely provide. We propose SlicePatch, a novel automated vulnerability repair framework for PHP web applications. SlicePatch leverages PoC-driven dynamic profiling to capture runtime program behavior and retain vulnerability-specific code paths in a context-aware manner. The isolated vulnerable code slices, distilled from the broader application codebase, guide LLMs to generate precise patches while cutting invocation cost. We pioneer directed differential fuzzing that helps validate and refine patch candidates iteratively without requiring test suites. Our extensive evaluation across 96 real-world vulnerabilities and LLMs shows that SlicePatch attains a repair success rate, significantly outperforming baselines by over .
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter AnalysisPenghui Li, Wei Meng, Mingxue Zhang, Chenlin Wang 等S&P 2024 · 被引用 6 次
- Well Begun is Half Done: Location-Aware and Trace-Guided Iterative Automated Vulnerability RepairZhenlei Ye, Xiaobing Sun, Sicong Cao, Lili Bo 等ICSE 2026
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
- Predator: Directed Web Application Fuzzing for Efficient Vulnerability ValidationChenlin Wang, Wei Meng, Changhua Luo, Penghui LiS&P 2025
- XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent FuzzingYoukun Shi, Yuan Zhang, Tianhao Bai, Feng Xue 等USENIX Security 2025
