Finding Fixed Vulnerabilities with Off-the-Shelf Static Analysis

Finding Fixed Vulnerabilities with Off-the-Shelf Static Analysis
复制标题

DOI:
10.1109/eurosp57164.2023.00036
复制
发表时间:
2023-07
期刊:
2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P)
影响因子:
--
通讯作者:
T. Dunlap;Seaver Thorn;W. Enck;Bradley Reaves
T. Dunlap;Seaver Thorn;W. Enck;Bradley Reaves
中科院分区:
其他
文献类型:
--
作者:
T. Dunlap;Seaver Thorn;W. Enck;Bradley Reaves

文献摘要

被引文献

相似文献

软件依赖于定期修复漏洞的上游项目,但这些漏洞的文档通常不可靠或不可用。自动收集现有漏洞修复对于下游项目可靠地更新其依赖关系至关重要,因为现代软件中的依赖关系数量庞大。以前的努力完全依赖于不完整的数据库或不精确或不准确的上游存储库的统计分析。在本文中,我们引入差分警报分析(DAA)发现软件项目中的漏洞修复。与统计分析相反,DAA利用静态分析安全测试(SAST)工具,该工具对代码上下文和语义进行推理。我们提供了一个独立于语言的DAA实现,并表明对于基于Python和Java的项目,DAA对于漏洞修复的地面实况数据集具有很高的精度-即使使用噪声和低精度的SAST工具。然后,我们在两个大规模的实证研究中使用DAA,涵盖了几个著名的生态系统,发现了数百个已解决的警报,其中包括许多从未公开披露的警报。因此,DAA为软件项目、代码分析工具、漏洞数据库和研究人员提供了一个强大、准确的原语,以表征和增强软件供应链的安全性。
Software depends on upstream projects that regularly fix vulnerabilities, but the documentation of those vulnerabilities is often unreliable or unavailable. Automating the collection of existing vulnerability fixes is essential for downstream projects to reliably update their dependencies due to the sheer number of dependencies in modern software. Prior efforts rely solely on incomplete databases or imprecise or inaccurate statistical analysis of upstream repositories. In this paper, we introduce Differential Alert Analysis (DAA) to discover vulnerability fixes in software projects. In contrast to statistical analysis, DAA leverages static analysis security testing (SAST) tools, which reason over code context and semantics. We provide a language-independent implementation of DAA and show that for Python and Java based projects, DAA has high precision for a ground-truth dataset of vulnerability fixes — even with noisy and low-precision SAST tools. We then use DAA in two large-scale empirical studies covering several prominent ecosystems, finding hundreds of resolved alerts, including many never publicly disclosed. DAA thus provides a powerful, accurate primitive for software projects, code analysis tools, vulnerability databases, and researchers to characterize and enhance the security of software supply chains.