REACT: IR-Level Patch Presence Test for Binary
Qi Zhan, Xing Hu, Xin Xia, Shanping Li
摘要
Patch presence test is critical in software security to ensure that binary files have been patched for known vulnerabilities. It is challenging due to the semantic gap between the source code and the binary, and the small and subtle nature of patches. In this paper, we propose React, the first patch presence test approach on IR-level. Based on the IR code compiled from the source code and the IR code lifted from the binary, we first extract four types of feature (return value, condition, function call, and memory store) by executing the program symbolically. Then, we refine the features from the source code and rank them. Finally, we match the features to determine the presence of a patch with an SMT solver to check the equivalence of features at the semantic level.
To evaluate our approach, we compare it with state-of-the-art approaches, BinXray and PS3, on a dataset containing binaries compiled from different compilers and optimization levels. Our experimental results show that React achieves scores of 0.88, 0.98, and 0.93, in terms of precision, recall, and F1 score, respectively. React outperforms the baselines by 39% and 12% in terms of the F1 score, while the testing speed of our approach is 2x faster than BinXray and 100x faster than PS3. Furthermore, we conduct an ablation study to evaluate the effectiveness of each component in React, which shows that SMT solver and refinement can contribute to 16% and 10% improvement in terms of the F1 score, respectively.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Enhancing Semantic-Aware Binary Diffing with High-Confidence Dynamic Instruction AlignmentChengfeng Ye, Anshunkang Zhou, Charles ZhangNDSS 2026 · 被引用 2 次
- IsolatOS: Detecting Double Fetch Bugs in COTS RTOS by Re-enabling Kernel IsolationYingjie Cao, Xiaogang Zhu, Dean Sullivan, Haowei Yang 等NDSS 2026 · 被引用 1 次
- Lares: LLM-driven Code Slice Semantic Search for Patch Presence TestingSiyuan Li, Yaowen Zheng, Hong Li, Jingdong Guo 等ASE 2025 · 被引用 1 次
- Diffploit: Facilitating Cross-Version Exploit Migration for Open Source Library VulnerabilitiesZirui Chen, Zhipeng Xue, Jiayuan Zhou, Xing Hu 等ICSE 2026
- SBridge: Identifying Source-to-Binary Function Similarity via Cross-Domain Control Block MatchingHeedong Yang, Jeongwoo Lee, Hajin Yun, Seunghoon WooFSE 2026
它引用的顶会 Paper14
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- Precise and Accurate Patch Presence Test for BinariesHang Zhang, Zhiyun QianUSENIX Security 2018 · 被引用 91 次
- Patch based vulnerability matching for binary programsYifei Xu, Zhengzi Xu, Bihuan Chen, Fu Song 等ISSTA 2020 · 被引用 74 次
- PDiff: Semantic-based Patch Presence Testing for Downstream KernelsZheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen 等CCS 2020 · 被引用 54 次
相关 Paper
- PS3: Precise Patch Presence Test based on Semantic Symbolic SignatureQi Zhan, Xing Hu, Zhiyang Li, Xin Xia 等ICSE 2024 · 被引用 4 次
- PPT4J: Patch Presence Test for Java BinariesZhiyuan Pan, Xing Hu, Xin Xia, Xian Zhan 等ICSE 2024 · 被引用 6 次
- VeriBin: Adaptive Verification of Patches at the Binary LevelHongwei Wu, Jianliang Wu, Ruoyu Wu, Ayushi Sharma 等NDSS 2025
- A Comprehensive Empirical Analysis of Patch Presence Testing: Capabilities, Limitations, and Paths ForwardXiaobei Zhang, Yaowen Zheng, Wu Luo, Shijun Zhao 等ISSTA 2026
- BScout: Direct Whole Patch Presence Test for Java ExecutablesJiarun Dai, Yuan Zhang, Zheyue Jiang, Yingtian Zhou 等USENIX Security 2020
