跳到主要导航 跳到搜索 跳到主要内容

PatUntrack: Automated Generating Patch Examples for Issue Reports without Tracked Insecure Code

  • Ziyou Jiang*
  • , Lin Shi
  • , Guowei Yang
  • , Qing Wang*
  • *此作品的通讯作者
  • State Key Laboratory of Intelligent Game
  • CAS - Institute of Software
  • University of Chinese Academy of Sciences
  • University of Queensland

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Security patches are essential for enhancing the stability and robustness of projects in the open-source software community. While vulnerabilities are officially expected to be patched before being disclosed, patching vulnerabilities is complicated and remains a struggle for many organizations. To patch vulnerabilities, security practitioners typically track vulnerable issue reports (IRs), and analyze their relevant insecure code to generate potential patches. However, the relevant insecure code may not be explicitly specified and practitioners cannot track the insecure code in the repositories, thus limiting their ability to generate patches. In such cases, providing examples of insecure code and the corresponding patches would benefit the security developers to better locate and resolve the actual insecure code. In this paper, we propose PatUntrack, an automated approach to generating patch examples from IRs without tracked insecure code. PatUntrack utilizes auto-prompting to optimize the Large Language Model (LLM) to make it applicable for analyzing the vulnerabilities described in IRs and generating appropriate patch examples. Specifically, it first generates the completed description of the Vulnerability-Triggering Path (VTP) from vulnerable IRs. Then, it corrects potential hallucinations in the VTP description with external golden knowledge. Finally, it generates Top-K pairs of Insecure Code and Patch Example based on the corrected VTP description. To evaluate the performance of PatUntrack, we conducted experiments on 5,465 vulnerable IRs. The experimental results show that PatUntrack can obtain the highest performance and improve the traditional LLM baselines by +17.7% (MatchFix) and +14.6% (Fix@10) on average in patch example generation. Furthermore, PatUntrack was applied to generate patch examples for 76 newly disclosed vulnerable IRs. 27 out of 37 replies from the authors of these IRs confirmed the usefulness of the patch examples generated by PatUntrack, indicating that they can benefit from these examples for patching the vulnerabilities.

源语言英语
主期刊名Proceedings - 2024 39th ACM/IEEE International Conference on Automated Software Engineering, ASE 2024
出版商Association for Computing Machinery, Inc
1-13
页数13
ISBN(电子版)9798400712487
DOI
出版状态已出版 - 27 10月 2024
活动39th ACM/IEEE International Conference on Automated Software Engineering, ASE 2024 - Sacramento, 美国
期限: 28 10月 20241 11月 2024

出版系列

姓名Proceedings - 2024 39th ACM/IEEE International Conference on Automated Software Engineering, ASE 2024

会议

会议39th ACM/IEEE International Conference on Automated Software Engineering, ASE 2024
国家/地区美国
Sacramento
时期28/10/241/11/24

学术指纹

探究 'PatUntrack: Automated Generating Patch Examples for Issue Reports without Tracked Insecure Code' 的科研主题。它们共同构成独一无二的学术指纹。

引用此