arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

为何不一次性彻底修复?开源软件中漏洞修复多个补丁的实证研究

Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software

Weiliang Qi, Youpeng Li, Xinda Wang

arXiv 2607.13206首次发表:更新:

AI 中文总结

研究开源软件多补丁漏洞修复,通过人工检查1646条记录开发分类法,比较多补丁与单补丁修复特征及类别间特征变化,评估检测方法,为多补丁修复研究提供新见解和基础。

AI 中文摘要

开源软件的安全补丁是漏洞修复研究和实践的基础资源。然而,分析和应用多个补丁仍具有挑战性,尤其是确定漏洞在补丁序列中的何时被完全修复。本文对多补丁漏洞修复进行系统分析,关注其根本原因、特征以及在修复过程中验证修复状态的方法。通过人工检查1646条多补丁修复记录,基于原因开发了一个有三个主要类别和六个子类别的分类法。然后比较多补丁修复与单补丁修复的不同特征,并分析各类别间的特征变化。此外,评估了用于在多补丁修复期间验证完全修复的代表性漏洞检测方法。研究结果为多补丁修复提供了新见解,为该领域未来研究奠定了基础。

英文摘要

Security patches for open-source software constitute a foundational resource for vulnerability remediation research and practice. However, analyzing and applying multiple patches remains challenging, especially when trying to determine at what point in a patch sequence a vulnerability is fully remediated. This paper presents a systematic analysis of multi-patch vulnerability fixes, focusing on their root causes, characteristics, and methods for verifying remediation status throughout the fixing process. Through a manual examination of 1,646 multi-patch fix records, we develop a taxonomy with three primary categories and six subcategories based on their causes. We then compare the distinctive characteristics of multi-patch fixes with those of single-patch fixes and analyze feature variations across categories. In addition, we assess representative vulnerability detection methods for validating complete remediation during multi-patch fixing. Our findings provide new insights into multi-patch fixes and lay a foundation for future research in this field.

CommentsAccepted at ESORICS 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑