Lune

USENIX Security2026顶会

Patch-Guided Vulnerability Detection: Extracting Java API Security Rules via Attack–Defense Cross-Analysis

Bofei Chen, Shuang Liao, Lei Zhang, Chibin Zhang, Mathias Payer, Yuan Zhang

出版方
2026年份

摘要

Security-sensitive APIs are critical components in modern Java applications, yet improper usage of these APIs frequently leads to severe vulnerabilities such as remote code execution. Existing methods for generating API security rules are limited as they rely on incomplete documentation or infer patterns from source code based on discovered inconsistencies.

We introduce VULGENIE, a patch-driven framework that extracts precise API security rules from confirmed security patches to then detect API misuse vulnerabilities. VULGENIE addresses three key challenges. First, it isolates violated constraints and defenses-related changes from noisy patches using our novel modification behavior dependency patch graph datastructure. Second, it identifies protected security-sensitive APIs and synthesizes rules through attack-defense crossvalidation. Third, it scales analysis with adaptive, deviationguided static analysis to balance precision and performance. Evaluated on 150 recent Java security patches, VULGENIE extracts 198 correct API security rules with 81.82% precision, uncovering 177 rules absent in CodeQL. On ten popular Java applications, VULGENIE detects 46 0-day vulnerabilities, substantially outperforming state-of-the-art works. Through our responsible vulnerability disclosure, 26 vulnerabilities have already been fixed with ten CVE identifiers assigned.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper20

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖