arrow
返回

An Abstract Syntax Tree based static fuzzing mutation for vulnerability evolution analysis

delete2023-06-01
delete45
PRE
AI
Z
Zheng Wei
P
Peiran Deng
K
Kui Gui
X
Xiaoxue Wu *
DOI:10.1016/j.infsof.2023.107194delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Context: Zero-day vulnerabilities are highly destructive and sudden. However, traditional static and dynamic testing methods cannot efficiently detect them. Objective: In this paper, a static fuzzy mutation method for program code is studied. This method can improve the efficiency of mutation sample generation according to the vulnerability evolution law, thus promoting the development of zero-day vulnerability detection methods based on deep learning techniques. Method: A static fuzzy mutation method based on the Abstract Syntax Tree (AST) is proposed. Under the guidance of software vulnerability evolution law, potential evolution paths that threaten program security are detected, and mutation samples containing vulnerabilities are generated at the syntax tree level based on the paths. To verify the effectiveness of static fuzzy mutation based on ASTs, this paper starts with Concurrent Use After Free (CUAF) homologous vulnerability. It uses multi-threaded programs to perform vulnerability feature statement insertion processing to infer the optimal mutation operator execution sequence corresponding to CUAF vulnerabilities triggered by data competition. The Linux kernel code is used to verify whether it can effectively reduce the number of invalid mutation samples. Results: In this paper, we filter the code fragments in the Linux kernel public code containing CUAF vulnerability fix commits and perform static fuzzy mutation on the fix versions of the vulnerabilities to reproduce the vulnerabilities of this type triggered by these code fragments on the timeline. We compare the process with the execution of the random mutation operator in traditional detection methods horizontally and improve the efficiency by 42.4% on average. Conclusion: The static fuzzy mutation based on the AST is effective in stages. When this method is explored in more vulnerability-type evolution laws, it is expected to promote the development of the zero-day vulnerability active detection technology framework.
Keyword:
Static fuzzy mutation
Abstract Syntax Tree
Potential evolution paths
Concurrent Use After Free
Multi-threaded programs

期刊

Information and Software Technology 封面图
Information and Software Technology
IF:
4.3
论文数:
3.8K
被引数:
7.7K

机构

N
Northwestern Polytechnical University
学者数:
4.6W
论文数: 3.7W
被引数: 5.3W
Y
Yangzhou University
学者数:
2.8W
论文数: 1.9W
被引数: 3.3W
引用论文

引用论文

The impact factors on the performance of machine learning-based vulnerability detection: A comparative study
err2020-10-01
err32
PREAI
errZheng, Wei; Gao, Jialiang; Wu, Xiaoxue; Liu, Fengyu; Xun, Yuxing; Liu, Guoliang; Chen, Xiang
err分享
err收藏
Predicting Vulnerable Software Components via Text Mining
err2014-10-01
err266
errOAAI
errScandariato, Riccardo; Walden, James; Hovsepyan, Aram; Joosen, Wouter
err分享
err收藏
Kinematical changes in swimming front Crawl and Breaststroke with the AquaTrainer® snorkel
err2010-04-09
err0
PREAI
errTiago Barbosa; António José Silva; António Malvas Reis; Mário Costa; Nuno Garrido; Fernando Policarpo; Victor Machado Reis
err分享
err收藏
Effects of Adjuvants to Local Anaesthetics on Their Duration
err2008-12-30
err0
PREAI
errH. G. HASSAN; B. ÅKERMAN; H. RENCK; B. LINDBERG; B. LINDQUIST
err分享
err收藏