BScout: Direct Whole Patch Presence Test for Java Executables
Jiarun Dai, Yuan Zhang, Zheyue Jiang, Yingtian Zhou, Junyan Chen, Xinyu Xing, Xiaohan Zhang, Xin Tan, Min Yang, Zhemin Yang
摘要
To protect end-users and software from known vulnerabilities, it is crucial to apply security patches to affected executables timely. To this end, patch presence tests are proposed with the capability of independently investigating patch application status on a target without source code. Existing work on patch presence testing adopts a signature-based approach. To make a trade-off between the uniqueness and the stability of the signature, existing work is limited to use a small and localized patch snippet (instead of the whole patch) for signature generation, so they are inherently unreliable. In light of this, we present BSCOUT, which directly checks the presence of a whole patch in Java executables without generating signatures. BSCOUT features several new techniques to bridge the semantic gap between source code and bytecode instructions during the testing, and accurately checks the fine-grained patch semantics in the whole target executable. We evaluate BScout with 194 CVEs from the Android framework and third-party libraries. The results show that it achieves remarkable accuracy with and without line number information (i.e., debug information) presented in a target executable. We further apply BSCOUT to perform a large-scale patch application practice study with 2,506 Android system images from 7 vendors. Our study reveals many findings that have not yet been reported.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- PDiff: Semantic-based Patch Presence Testing for Downstream KernelsZheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen 等CCS 2020 · 被引用 54 次
- Locating the Security Patches for Disclosed OSS Vulnerabilities with Vulnerability-Commit Correlation RankingXin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao 等CCS 2021 · 被引用 43 次
- Tracking patches for open source software vulnerabilitiesCongying Xu, Bihuan Chen, Chenhao Lu, Kaifeng Huang 等FSE 2022 · 被引用 34 次
- Facilitating Vulnerability Assessment through PoC MigrationJiarun Dai, Yuan Zhang, Hailong Xu, Haiming Lyu 等CCS 2021 · 被引用 26 次
- Trust, But Verify: A Longitudinal Analysis Of Android OEM Compliance and CustomizationAndrea Possemato, Simone Aonzo, Davide Balzarotti, Yanick FratantonioS&P 2021 · 被引用 21 次
它引用的顶会 Paper8
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin 等CCS 2017 · 被引用 682 次
- Scalable Graph-based Bug Search for Firmware ImagesQian Feng, Rundong Zhou, Chengcheng Xu, Yao Cheng 等CCS 2016 · 被引用 456 次
- VUDDY: A Scalable Approach for Vulnerable Code Clone DiscoverySeulbae Kim, Seunghoon Woo, Heejo Lee, Hakjoo OhS&P 2017 · 被引用 388 次
- discovRE: Efficient Cross-Architecture Identification of Bugs in Binary CodeSebastian Eschweiler, Khaled Yakdan, Elmar Gerhards-PadillaNDSS 2016 · 被引用 342 次
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
相关 Paper
- PPT4J: Patch Presence Test for Java BinariesZhiyuan Pan, Xing Hu, Xin Xia, Xian Zhan 等ICSE 2024 · 被引用 6 次
- Precise and Accurate Patch Presence Test for BinariesHang Zhang, Zhiyun QianUSENIX Security 2018 · 被引用 91 次
- PS3: Precise Patch Presence Test based on Semantic Symbolic SignatureQi Zhan, Xing Hu, Zhiyang Li, Xin Xia 等ICSE 2024 · 被引用 4 次
- InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on AndroidYaohui Chen, Yuping Li, Long Lu, Yueh-Hsun Lin 等NDSS 2018 · 被引用 32 次
- A Comprehensive Empirical Analysis of Patch Presence Testing: Capabilities, Limitations, and Paths ForwardXiaobei Zhang, Yaowen Zheng, Wu Luo, Shijun Zhao 等ISSTA 2026
