arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Not In My Git Yard:在提交与发布时捕获后门

Not In My Git Yard: Catching Backdoors at Commit and Release Time

Dimitri Kokkonis, Michaël Marcozzi, Stefano Zacchiroli

arXiv 2607.26719首次发表:更新:

AI 中文总结

本研究提出自动化方法Lily,将后门检测集成到CI管道与发布审查工作流,结合代码变更分析与模糊测试,可高准确率检测代码级后门,抵御对抗性尝试,阻止现实世界后门事件。

AI 中文摘要

代码级后门是指通过秘密触发器授予隐藏权限的隐蔽代码变更,对开源软件构成持续威胁。已知通过恶意提交、被篡改的发布包或被入侵的第三方依赖向广泛使用的项目注入此类后门的尝试,仅靠运气和人工审查才被阻止。现有的持续集成(CI)管道无法检测这些攻击,而下游二进制分析工具需要大量人工工作。在这项工作中,我们提出了Lily,一种增强开源开发和发布流程以抵御后门注入的自动化方法。Lily将后门检测机制集成到(1)CI管道中以阻止恶意提交,以及(2)发布审查工作流中,以防止被篡改的发布或被入侵的依赖进入Linux发行版等大型生态系统。Lily有两个关键贡献:首先,它增强了与CI兼容的模糊测试,具备基于历史和当前软件执行检测可疑行为触发器的能力,这使得快速、精确的后门检测适用于CI和更新验证工作流;其次,它将代码变更分析与模糊测试数据相结合,即使发布更新修改了数百万行代码,也能精确指向维护者后门暴露的代码区域。我们还概述了攻击者可能用来规避Lily的五种策略,并评估了相应的防御措施。我们对数百个良性和带后门的提交及发布进行的实验表明,Lily实现了高检测准确率和低误报率,可靠识别恶意代码,抵御对抗性尝试,且本可以阻止现实世界的后门事件。

英文摘要

Code-level backdoors-stealthy code changes that grant hidden privileges via secret triggers-pose a persistent threat to opensource software. Known attempts to inject such backdoors into widely used projects through malicious commits, tampered release packages, or compromised third-party dependencies, were stopped only by luck and manual review. Existing Continuous Integration (CI) pipelines cannot detect these attacks, and downstream binary analysis tools require substantial manual effort. In this work, we present Lily, an automated approach that strengthens open-source development and release processes against backdoor injection. Lily integrates a backdoor detection mechanism into (1) CI pipelines to block malicious commits, and (2) release vetting workflows to prevent tampered releases or compromised dependencies from entering large ecosystems, such as Linux distributions. Lily offers two key contributions. First, it enhances CI-compatible fuzzing with the capability to detect triggers of suspicious behavior based on historical and current software executions. This enables fast, precise backdoor detection suitable for both CI and update validation workflows. Second, it combines code change analysis with fuzzing data to precisely point maintainers to backdoor-revealing code regions, even when release updates modify millions of lines of code. We also outline five strategies attackers could use to evade Lily, and evaluate corresponding defenses. Our experiments across hundreds of benign and backdoored commits and releases show that Lily achieves high detection accuracy with low false alarm rates, reliably identifies malicious code, resists adversarial attempts, and would have prevented real-world backdoor incidents.

Journal ref41st IEEE/ACM International Conference on Automated Software Engineering (ASE 2026), Oct 2026, Munich (Allemagne), Germany

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑