Facilitating Vulnerability Assessment through PoC Migration

被引:7
|
作者
Dai, Jiarun [1 ]
Zhang, Yuan [1 ]
Xu, Hailong [1 ]
Lyu, Haiming [1 ]
Wu, Zicheng [1 ]
Xing, Xinyu [2 ]
Yang, Min [1 ]
机构
[1] Fudan Univ, Shanghai, Peoples R China
[2] Penn State Univ, University Pk, PA 16802 USA
来源
CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2021年
基金
上海市自然科学基金; 中国国家自然科学基金;
关键词
Vulnerability Assessment; Trace Alignment; PoC Adjustment; CODE; ROBUST;
D O I
10.1145/3460120.3484594
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent research shows that, even for vulnerability reports archived by MITRE/NIST, they usually contain incomplete information about the software's vulnerable versions, making users of under-reported vulnerable versions at risk. In this work, we address this problem by introducing a fuzzing-based method. Technically, this approach first collects the crashing trace on the reference version of the software. Then, it utilizes the trace to guide the mutation of the PoC input so that the target version could follow the trace similar to the one observed on the reference version. Under the mutated input, we argue that the target version's execution could have a higher chance of triggering the bug and demonstrating the vulnerability's existence. We implement this idea as an automated tool, named VULSCOPE. Using 30 real-world CVEs on 470 versions of software, VULSCOPE is demonstrated to introduce no false positives and only 7.9% false negatives while migrating PoC from one version to another. Besides, we also compare our method with two representative fuzzing tools AFL and AFLGO. We find VULSCOPE outperforms both of these existing techniques while taking the task of PoC migration. Finally, by using VULSCOPE, we identify 330 versions of software that MITRE/NIST fails to report as vulnerable.
引用
收藏
页码:3300 / 3317
页数:18
相关论文
共 50 条
  • [41] Revealing the exploitability of heap overflow through PoC analysis
    Shen, Qintao
    Meng, Guozhu
    Chen, Kai
    CYBERSECURITY, 2024, 7 (01):
  • [42] Overexpression of NREP Promotes Migration and Invasion in Gastric Cancer Through Facilitating Epithelial-Mesenchymal Transition
    Liu, Yuan-jie
    Zeng, Shu-hong
    Hu, Yi-dou
    Zhang, Yong-hua
    Li, Jie-pin
    FRONTIERS IN CELL AND DEVELOPMENTAL BIOLOGY, 2021, 9
  • [43] Facilitating H migration on graphene by adsorbing on Au
    Hinuma, Yoyo
    Mori, Kohsuke
    COMPUTATIONAL AND THEORETICAL CHEMISTRY, 2024, 1238
  • [44] Facilitating ICME Through Platformization
    Gautham, B. P.
    Reddy, Sreedhar
    Das, Prasenjit
    Malhotra, Chetan
    PROCEEDINGS OF THE 4TH WORLD CONGRESS ON INTEGRATED COMPUTATIONAL MATERIALS ENGINEERING (ICME 2017), 2017, : 93 - 102
  • [45] Facilitating through collaborative technology
    Hudson, M
    Null, P
    BEST PRACTICES IN ORGANIZATIONS AND TEAMS, 2000 PROCEEDINGS, 2000, : 31 - 43
  • [46] Theory and practice in assessing vulnerability to climate change and facilitating adaptation
    Kelly, PM
    Adger, WN
    CLIMATIC CHANGE, 2000, 47 (04) : 325 - 352
  • [47] Migraine Mutations Increase Stroke Vulnerability by Facilitating Ischemic Depolarizations
    Eikermann-Haerter, Katharina
    Lee, Jeong Hyun
    Yuzawa, Izumi
    Liu, Christina H.
    Zhou, Zhipeng
    Shin, Hwa Kyoung
    Zheng, Yi
    Qin, Tao
    Kurth, Tobias
    Waeber, Christian
    Ferrari, Michel D.
    van den Maagdenberg, Arn M. J. M.
    Moskowitz, Michael A.
    Ayata, Cenk
    CIRCULATION, 2012, 125 (02) : 335 - U345
  • [48] Review and assessment of models for predicting the migration of radionuclides through rivers
    Monte, L
    Boyer, P
    Brittain, JE
    Håkanson, L
    Lepicard, S
    Smith, JT
    JOURNAL OF ENVIRONMENTAL RADIOACTIVITY, 2005, 79 (03) : 273 - 296
  • [49] Vulnerability Assessment of Electric Power Systems Through Identification and Ranking of Vulnerable Areas
    Cepeda, Jaime C.
    Colome, Delia G.
    INTERNATIONAL JOURNAL OF EMERGING ELECTRIC POWER SYSTEMS, 2012, 13 (01):
  • [50] Structural damage and vulnerability assessment for service life estimation through MEDEA tool
    Zuccaro, G.
    Leone, M. F.
    COST ACTION C26: URBAN HABITAT CONSTRUCTIONS UNDER CATASTROPHIC EVENTS, 2010, : 731 - 740