跳到主要导航 跳到搜索 跳到主要内容

Beyond Tests: Program Vulnerability Repair via Crash Constraint Extraction

  • Xiang Gao
  • , Bo Wang*
  • , Gregory J. Duck
  • , Ruyi Ji
  • , Yingfei Xiong
  • , Abhik Roychoudhury
  • *此作品的通讯作者
  • National University of Singapore
  • Peking University

科研成果: 期刊稿件文章同行评审

摘要

Automated program repair is an emerging technology that seeks to automatically rectify program errors and vulnerabilities. Repair techniques are driven by a correctness criterion that is often in the form of a test suite. Such test-based repair may produce overfitting patches, where the patches produced fail on tests outside the test suite driving the repair. In this work, we present a repair method that fixes program vulnerabilities without the need for a voluminous test suite. Given a vulnerability as evidenced by an exploit, the technique extracts a constraint representing the vulnerability with the help of sanitizers. The extracted constraint serves as a proof obligation that our synthesized patch should satisfy. The proof obligation is met by propagating the extracted constraint to locations that are deemed to be "suitable"fix locations. An implementation of our approach (ExtractFix) on top of the KLEE symbolic execution engine shows its efficacy in fixing a wide range of vulnerabilities taken from the ManyBugs benchmark, real-world CVEs and Google's OSS-Fuzz framework. We believe that our work presents a way forward for the overfitting problem in program repair by generalizing observable hazards/vulnerabilities (as constraint) from a single failing test or exploit.

源语言英语
文章编号14
期刊ACM Transactions on Software Engineering and Methodology
30
2
DOI
出版状态已出版 - 3月 2021
已对外发布

指纹

探究 'Beyond Tests: Program Vulnerability Repair via Crash Constraint Extraction' 的科研主题。它们共同构成独一无二的指纹。

引用此