Precisely Characterizing Security Impact in a Flood of Patches via Symbolic Rule Comparison
Qiushi Wu, Yang He, Stephen McCamant, Kangjie Lu
摘要
A bug is a vulnerability if it has security impacts when triggered. Determining the security impacts of a bug is important to both defenders and attackers. Maintainers of large software systems are bombarded with numerous bug reports and proposed patches, with missing or unreliable information about their impact. Determining which few bugs are vulnerabilities is difficult, and bugs that a maintainer believes do not have security impact will be de-prioritized or even ignored. On the other hand, a public report of a bug with a security impact is a powerful first step towards exploitation. Adversaries may exploit such bugs to launch devastating attacks if defenders do not fix them promptly. Common practice is for maintainers to assess the security impacts of bugs manually, but the scaling and reliability challenges of manual analysis lead to missed vulnerabilities. We propose an automated approach, SID, to determine the security impacts for a bug given its patch, so that maintainers can effectively prioritize applying the patch to the affected programs. The insight behind SID is that both the effect of a patch (either submitted or applied) and security-rule violations (e.g., out-of-bound access) can be modeled as constraints that can be automatically solved. SID incorporates rule comparison, using under-constrained symbolic execution of a patch to determine the security impacts of an un-applied patch. SID can further automatically classify vulnerabilities based on their security impacts. We have implemented SID and applied it to bug patches of the Linux kernel and matching CVE-assigned vulnerabilities to evaluate its precision and recall. We optimized SID to reduce false positives, and our evaluation shows that, from 54K recent valid commit patches, SID detected 227 security bugs with at least 243 security impacts at a 97% precision rate. Critically, 197 of them were not reported as vulnerabilities before, leading to delayed or ignored patching in derivative programs. Even worse, 21 of them are still unpatched in the latest Android kernel. Once exploited, they can cause critical security impacts on Android devices. The evaluation results confirm that SID’s approach is effective and precise in automatically determining security impacts for a massive stream of bug patches.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper28
- An Investigation of the Android Kernel Patch EcosystemZheng Zhang, Hang Zhang, Zhiyun Qian, Billy LauUSENIX Security 2021 · 被引用 45 次
- Understanding and Detecting Disordered Error Handling with Precise Function PairingQiushi Wu, Aditya Pakki, Navid Emamdoost, Stephen McCamant 等USENIX Security 2021 · 被引用 31 次
- SyzDirect: Directed Greybox Fuzzing for Linux KernelXin Tan, Yuan Zhang, Jiadong Lu, Xin Xiong 等CCS 2023 · 被引用 25 次
- Interpreters for GNN-Based Vulnerability Detection: Are We There Yet?Yutao Hu, Suyuan Wang, Wenke Li, Junru Peng 等ISSTA 2023 · 被引用 21 次
- PatchScope: Memory Object Centric Patch DiffingLei Zhao, Yuncong Zhu, Jiang Ming, Yichen Zhang 等CCS 2020 · 被引用 21 次
它引用的顶会 Paper14
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- A Large-Scale Empirical Study of Security PatchesFrank Li, Vern PaxsonCCS 2017 · 被引用 273 次
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili 等CCS 2017 · 被引用 195 次
- SemFuzz: Semantics-based Automatic Generation of Proof-of-Concept ExploitsWei You, Peiyuan Zong, Kai Chen, XiaoFeng Wang 等CCS 2017 · 被引用 148 次
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 被引用 142 次
相关 Paper
- SyzScope: Revealing High-Risk Security Impacts of Fuzzer-Exposed Bugs in Linux kernelXiaochen Zou, Guoren Li, Weiteng Chen, Hang Zhang 等USENIX Security 2022
- SymBisect: Accurate Bisection for Fuzzer-Exposed VulnerabilitiesZheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou 等USENIX Security 2024 · 被引用 7 次
- OS-Aware Vulnerability Prioritization via Differential Severity AnalysisQiushi Wu, Yue Xiao, Xiaojing Liao, Kangjie LuUSENIX Security 2022
- Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints InferencesKangjie Lu, Aditya Pakki, Qiushi WuUSENIX Security 2019 · 被引用 97 次
- Sys: A Static/Symbolic Tool for Finding Good Bugs in Good (Browser) CodeFraser Brown, Deian Stefan, Dawson R. EnglerUSENIX Security 2020
