arrow
Return

PREXP: Uncovering and Exploiting Security-Sensitive Objects in the Linux Kernel

delete2025-01-01
delete0
PRE
AI
Z
Zuxin Chen
Y
Yaowen Zheng
李红 (Hong Li)
S
Siyuan Li
W
Weijie Wang
D
Dongliang Fang
Z
Zhiqiang Shi
L
Limin Sun
DOI:10.1109/TIFS.2025.3611149delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Security-Sensitive Objects (SSOs) are often critical components in the exploitation of Linux kernel memory corruption vulnerabilities. While existing research has advanced SSOs identification and classification, there remains a significant gap in systematically understanding how these objects can be effectively exploited in real-world security analysis. To address this challenge, we present PREXP, a novel approach to analyzing SSOs exploitability and automating the transformation of Proof-of-Concept (PoC) into exploitable states. Our approach encompasses three key techniques: (1) capability analysis and attribute modeling of vulnerable object (2) extraction and filtering of target SSOs and (3) automatically augmenting PoCs with SSO-specific code to create exploitation capabilities. To evaluate our approach, we tested our prototype on 30 public CVEs, successfully parsing vulnerable object in 22 cases (73.3%) and achieving accurate SSO matches in 18 (60.0%). PREXP outperformed state-of-the-art tools such as SCAVY and AlphaEXP in structure-matching, and enabled the generation of new Control Flow Hijacking Primitives (CFHPs) for 3 previously unexploited vulnerabilities, demonstrating its practical value in real-world exploit development.
Keywords:
Vulnerability exploitation
security-sensitive objects exploitation
kernel security

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

I
Institute of Information Engineering
Scholars:
325
Papers: 111
Citations: 439