arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.12723cs.CRcs.AIcs.SE

舱壁:容器逃逸漏洞的自动语义检测与修复

Bulkhead: Automated Semantic Detection and Remediation of Container Escape Vulnerabilities

Qiyuan Fan, Zhi Li, Junjie Li, XiaoFeng Wang, Bin Yuan, Deqing Zou

首次发表
浏览论文内容

中文总结 AI 辅助

研究容器逃逸漏洞,提出舱壁框架,集成大语言模型与形式化方法,利用多智能体系统通过多维知识模式识别修复漏洞,检测管道找漏洞并生成利用程序,补丁管道验证确保修复正确。

中文摘要 AI 辅助

容器生态系统中的文件系统隔离常因跨边界路径错误解析而被削弱,导致路径遍历漏洞。这些漏洞源于不安全的主机 - 容器交互,随着云系统为支持人工智能工作负载而将共享资源挂载到容器中,此类漏洞愈发普遍,现有防御不足。我们提出了舱壁,一个将大语言模型与形式化方法集成的自动框架,用于语义漏洞发现和修复。它使用多智能体系统通过从已知案例中归纳出的多维知识模式来识别和修复路径遍历漏洞,先定位跨边界交互入口点,再恢复执行路径,检测管道分析调用链识别漏洞并生成概念验证利用程序,补丁管道进行断言驱动验证确保修复正确性。

英文摘要

Filesystem isolation in container ecosystems is often weakened by cross-boundary path misresolution, causing path traversal (PaTra) vulnerabilities. These vulnerabilities stem from insecure host-container interactions and have become increasingly pervasive as cloud systems mount shared resources, such as GPUs and agent workspaces, into containers to support AI workloads. Existing defenses remain inadequate. Kernel-level protections are intrusive, can destabilize system calls, and have therefore not been accepted into the Linux mainline. Detection methods rely on static rule matching or manual code auditing. Static rules can flag path-related functions but fail to capture the semantics needed to determine whether a host-container interaction exists, causing many false positives. Manual review requires domain expertise, making it costly, inefficient, and difficult to scale. To address this threat, we present Bulkhead, an automated framework that integrates large language models (LLMs) with formal methods for semantic vulnerability discovery and remediation. Bulkhead uses a multi-agent system to identify and repair PaTra vulnerabilities through multi-dimensional knowledge patterns generalized from known cases. It first applies high-risk functional patterns to locate entry points for cross-boundary interactions in containerized code, then uses call-chain patterns to recover the corresponding execution paths at suitable depth. The Detection pipeline analyzes these call chains against the application scenarios and threat model, identifying vulnerabilities such as missing security checks and TOCTOU flaws in cross-boundary interactions, and generating proof-of-concept (PoC) exploits for validation. These PoCs then guide patch generation. To ensure remediation correctness, the Patch pipeline performs assertion-driven verification using predefined model-checking templates.

↑