arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CWEEP:用于CWE早期预防的词法静态分析框架

CWEEP: A Lexical Static Analysis Framework for CWE Early Prevention

Bryan Kwan, Benjamin Tan

arXiv 2607.29604首次发表:更新:

AI 中文总结

CWEEP是一种用于RTL安全弱点检测的静态分析框架,无需详细安全规范即可在RTL开发早期使用,能定位漏洞并提供修复建议,在3874个有漏洞模块数据集上的正确警告率达60.8%,远优于同类工具。

AI 中文摘要

随着硬件层成为攻击者的关注焦点,改进的硬件安全验证技术的需求比以往任何时候都更为重要。最先进的安全验证技术需要具有安全专业知识的人员付出大量手动工作,此外,还没有标准方法来定位寄存器传输级(RTL)代码中的故障所在。本文提出了CWEEP,一个用于检测RTL中安全弱点的静态分析框架。CWEEP不需要详细的安全规范,因此可在RTL开发的早期阶段使用,此时特性仍在构建中。此外,CWEEP可以识别RTL中潜在漏洞的确切位置,并在适用时支持自动代码修复建议。使用文献中的数据集,我们在一组带有手动插入漏洞的两个SoC设计以及一个包含3874个有漏洞模块的大语言模型生成的数据集上评估了CWEEP的性能。我们发现CWEEP的正确警告率高达60.8%,相比之下,同一数据集上之前工作中的工具正确警告率为17.5%。

英文摘要

As the hardware layer becomes a focus point for attackers, the need for improved hardware security verification techniques is more important than ever. State-of-the-art security verification techniques require significant manual effort from individuals with security expertise. Furthermore, there is no standard method to locate where the fault lies within the register transfer level (RTL) code. This paper presents CWEEP, a static analysis framework for detecting security weaknesses in RTL. CWEEP does not require a detailed security specification, so it can be used in the early stages of RTL development while properties are still under construction. Furthermore, CWEEP can identify the exact location in the RTL where the potential vulnerability resides and supports automatic code repair suggestions when applicable. Using datasets from the literature, we evaluate the performance of CWEEP on a set of two SoC designs with manually inserted bugs and on a large language model generated dataset, consisting of 3874 buggy modules. We find that CWEEP issues a correct warning up to 60.8% of the time. In contrast, the tool from a previous work issued a correct warning 17.5% of the time for the same dataset.

Comments12 pages, 9 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑