Detecting "0-Day" Vulnerability: An Empirical Study of Secret Security Patch in OSS

Detecting "0-Day" Vulnerability: An Empirical Study of Secret Security Patch in OSS
复制标题

DOI:
10.1109/dsn.2019.00056
复制
发表时间:
2019-06
期刊:
2019 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
Xinda Wang;Kun Sun;A. Batcheller;S. Jajodia
Xinda Wang;Kun Sun;A. Batcheller;S. Jajodia
中科院分区:
其他
文献类型:
--
作者:
Xinda Wang;Kun Sun;A. Batcheller;S. Jajodia

文献摘要

相似文献

开源软件(OSS)中的安全补丁不仅可以为已识别的漏洞提供安全修复,还可以将易受攻击的代码公开给攻击者。因此,装甲攻击者可能会滥用这些信息,对未打补丁的OSS版本发起N日攻击。防止此类 N 天攻击的最佳做法是立即将软件升级到最新版本。然而,出于对声誉和易于软件开发管理的考虑,软件供应商可能会选择在新版本中秘密修补其漏洞,而不向 CVE 报告,甚至在更改日志中提供任何明确的描述。当这些秘密修补的漏洞被装甲攻击者识别时,它们可以转化为强大的“0day”攻击,不仅可以利用该攻击来危害同一软件的未修补版本,还可以危害类似类型的OSS(例如SSL库),这些OSS可能由于代码克隆或类似的设计/实现逻辑而包含相同的漏洞。因此,识别秘密安全补丁并将这些“0 天”攻击的风险降低到至少“n 天”攻击至关重要。在本文中,我们开发了一个防御系统并实现了一个工具集来自动识别开源软件中的秘密安全补丁。为了区分安全补丁和其他补丁,我们首先建立一个安全补丁数据库,其中包含4700多个安全补丁映射到CVE列表中的记录。接下来,我们使用机器学习方法确定一组功能,以帮助区分安全补丁与非安全补丁。最后,我们使用代码克隆识别机制来发现类似类型的OSS中的类似补丁或漏洞。实验结果表明我们的方法可以取得良好的检测性能。对 OpenSSL、LibreSSL 和 BoringSSL 的案例研究发现了 12 个秘密安全补丁。
Security patches in open source software (OSS) not only provide security fixes to identified vulnerabilities, but also make the vulnerable code public to the attackers. Therefore, armored attackers may misuse this information to launch N-day attacks on unpatched OSS versions. The best practice for preventing this type of N-day attacks is to keep upgrading the software to the latest version in no time. However, due to the concerns on reputation and easy software development management, software vendors may choose to secretly patch their vulnerabilities in a new version without reporting them to CVE or even providing any explicit description in their change logs. When those secretly patched vulnerabilities are being identified by armored attackers, they can be turned into powerful "0-day" attacks, which can be exploited to compromise not only unpatched version of the same software, but also similar types of OSS (e.g., SSL libraries) that may contain the same vulnerability due to code clone or similar design/implementation logic. Therefore, it is critical to identify secret security patches and downgrade the risk of those "0-day" attacks to at least "n-day" attacks. In this paper, we develop a defense system and implement a toolset to automatically identify secret security patches in open source software. To distinguish security patches from other patches, we first build a security patch database that contains more than 4700 security patches mapping to the records in CVE list. Next, we identify a set of features to help distinguish security patches from non-security ones using machine learning approaches. Finally, we use code clone identification mechanisms to discover similar patches or vulnerabilities in similar types of OSS. The experimental results show our approach can achieve good detection performance. A case study on OpenSSL, LibreSSL, and BoringSSL discovers 12 secret security patches.