PatchScope: Memory Object Centric Patch Diffing

PatchScope: Memory Object Centric Patch Diffing
复制标题

DOI:
10.1145/3372297.3423342
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Lei Zhao;Yuncong Zhu;Jiang Ming;Yichen Zhang;Haotian Zhang;Heng Yin
Lei Zhao;Yuncong Zhu;Jiang Ming;Yichen Zhang;Haotian Zhang;Heng Yin
中科院分区:
其他
文献类型:
--
作者:
Lei Zhao;Yuncong Zhu;Jiang Ming;Yichen Zhang;Haotian Zhang;Heng Yin

文献摘要

被引文献

相似文献

软件补丁是对抗漏洞的最重要机制之一。为了揭开底层补丁细节的神秘面纱,提出了补丁差异分析(也称为补丁比较)技术来查找修补程序和未修补程序的二进制代码之间的差异。考虑到复杂的安全补丁,补丁比较不仅可以正确定位补丁更改,还可以为理解补丁详细信息和修复的漏洞提供充分的解释。不幸的是,现有的补丁比较技术都不能满足这些要求。在本研究中,我们首先对安全补丁的代码更改进行了大规模研究,以更好地了解其模式。然后我们指出补丁差异的几个挑战和设计原则。为了解决上述挑战,我们设计了一种动态补丁比较技术 PatchScope。我们的技术受到两个关键观察的启发:1)程序处理输入的方式揭示了丰富的语义信息,2)大多数内存损坏补丁通过更新与输入相关的数据结构的操作来规范对格式错误输入的处理。 PatchScope 的核心是一种新的语义感知程序表示形式,即内存对象访问序列,它描述了程序如何引用数据结构来操作输入。该表示不仅可以提供简洁的补丁差异,还可以提供丰富的补丁上下文信息,例如输入补丁相关性。此类信息可以解释补丁差异,并进一步帮助安全分析师了解补丁详细信息、定位漏洞根本原因,甚至检测有错误的补丁。
Software patching is one of the most significant mechanisms to combat vulnerabilities. To demystify underlying patch details, the techniques of patch differential analysis (a.k.a. patch diffing) are proposed to find differences between patched and unpatched programs' binary code. Considering the sophisticated security patches, patch diffing is expected to not only correctly locate patch changes but also provide sufficient explanation for understanding patch details and the fixed vulnerabilities. Unfortunately, none of the existing patch diffing techniques can meet these requirements. In this study, we first perform a large-scale study on code changes of security patches for better understanding their patterns. We then point out several challenges and design principles for patch diffing. To address the above challenges, we design a dynamic patch diffing technique PatchScope. Our technique is motivated by two key observations: 1) the way that a program processes its input reveals a wealth of semantic information, and 2) most memory corruption patches regulate the handling of malformed inputs via updating the manipulations of input-related data structures. The core of PatchScope is a new semantics-aware program representation, memory object access sequence, which characterizes how a program references data structures to manipulate inputs. The representation can not only deliver succinct patch differences but also offer rich patch context information such as input-patch correlations. Such information can interpret patch differences and further help security analysts understand patch details, locate vulnerability root causes, and even detect buggy patches.