One-day vulnerabilities pose significant risks due to delayed or incomplete patch adoption. Generating proof-of-concept (PoC) inputs is therefore essential for assessing real-world impact. The key challenge is identifying necessary constraints for triggering the vulnerability and solving them effectively. Existing directed fuzzing approaches prioritize inputs toward target locations, but neither explicitly identify necessary constraints nor solve them effectively, relying instead on target-distance feedback and random mutation. Agentic approaches show strong potential through code reasoning and structured input generation, but goal drift in long-horizon reasoning limits their effectiveness. DIG addresses this challenge by exploiting a key property of one-day vulnerabilities: patches often reveal necessary preconditions for triggering. DIG uses an LLM to analyze the patch and synthesize an oracle making these conditions explicit. The oracle supports effective PoC generation at two levels. At the high level, DIG performs oracle-guided generator evolution, where an agent infers and solves constraints to satisfy the oracle. At the low level, DIG instruments the oracle into the target program and uses branch-distance feedback to guide random mutation in directed fuzzing. Evaluation shows DIG outperforms 2 state-of-the-art agents and 10 fuzzers across 138 real-world CVEs. DIG triggers 80 vulnerabilities, surpassing prior results and outperforming the best baseline by 40% (57 vs. 80 CVEs). Notably, DIG exclusively triggers 9 vulnerabilities no existing technique can trigger. Compared to the average of other tools, DIG triggers vulnerabilities faster in 92.9% of cases, achieving over 100x speedup in 48.8% of cases, with a maximum speedup of 3,664x. Beyond one-day PoC generation, DIG uncovers 6 previously unknown vulnerabilities in widely deployed libraries, enabling zero-day discovery.


翻译:单日漏洞因补丁部署延迟或不完整而构成重大风险,因此生成概念验证(PoC)输入对于评估其现实影响至关重要。关键挑战在于识别触发漏洞所需的约束条件并有效求解。现有定向模糊测试方法将输入导向目标位置,但既未显式识别必要约束也未能有效求解,而是依赖目标距离反馈和随机变异。基于智能体的方法通过代码推理和结构化输入生成展现出潜力,但长程推理中的目标漂移限制了其有效性。DIG通过利用单日漏洞的一个关键特性来应对这一挑战:补丁往往揭示了触发漏洞所需的必要前置条件。DIG使用大语言模型分析补丁并合成一个显式化这些条件的预言函数。该预言函数在两层面上支持有效的PoC生成。在高层,DIG执行预言引导的生成器进化,其中智能体推断并求解约束以满足预言函数。在低层,DIG将预言函数注入目标程序,并使用分支距离反馈指导定向模糊测试中的随机变异。评估表明,在138个真实世界CVE上,DIG超越了2个最先进的智能体方案和10个模糊测试工具。DIG成功触发了80个漏洞,超越了先前结果,并以40%的提升优于最佳基线(57 vs 80个CVE)。值得注意的是,DIG独占了现有技术无法触发的9个漏洞。相较于其他工具的平均水平,DIG在92.9%的案例中更快触发漏洞,其中48.8%的案例实现了超过100倍加速,最大加速比达3,664倍。除单日漏洞PoC生成外,DIG还在广泛部署的库中发现了6个先前未知的漏洞,实现了零日漏洞的发现。

0
下载
关闭预览

相关内容

Xsser 一款自动检测XSS漏洞工具
黑白之道
14+阅读 · 2019年8月26日
图嵌入(Graph embedding)综述
人工智能前沿讲习班
449+阅读 · 2019年4月30日
一文读懂目标检测:R-CNN、Fast R-CNN、Faster R-CNN、YOLO、SSD
七月在线实验室
11+阅读 · 2018年7月18日
国家自然科学基金
4+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
VIP会员
最新内容
印度精确打击与指挥架构的断层
专知会员服务
4+阅读 · 7月20日
美空军AI完成F-16战斗机自主空战历史性试飞
专知会员服务
6+阅读 · 7月20日
深入Project Maven:为何人工智能在战场上依然失灵
锻造未来士兵:外骨骼、基因工程与赛博格
专知会员服务
7+阅读 · 7月19日
《无人机蜂群通信技术研究》50页
专知会员服务
10+阅读 · 7月19日
相关VIP内容
相关基金
国家自然科学基金
4+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员