基于数字孪生的AArch64机器代码漏洞检测
Vulnerability Detection in AArch64 Machine Code Using a Digital Twin
浏览论文内容
中文总结 AI 辅助
本文提出可解释数字孪生,通过将漏洞规则编译为有限自动机检测AArch64机器代码的三类CWE漏洞,检测结果可提供可复现解释,无需SMT求解器。
中文摘要 AI 辅助
本文提出一种可解释的数字孪生,用于在无源代码的情况下检测AArch64机器代码中的漏洞。该数字孪生复现程序的具体执行过程,保留寄存器、处理器标志、内存和动态分配块的状态。每条指令被转换为包含指令名称、操作数值和指令后状态的跟踪事件。漏洞被表示为带测试的Kleene代数中的符号规则:每条规则指定事件序列和机器状态上的谓词,该方法不仅能检测孤立的不安全指令,还能检测多步执行模式。规则被编译为有限自动机,无需使用SMT求解器即可扫描跟踪。实验评估涵盖三类CWE:整数溢出(CWE-190)、空指针解引用(CWE-476)和堆缓冲区溢出(CWE-122)。系统检测到所有三个预定义漏洞,且未对安全跟踪产生任何报告。每个检测结果包含触发的规则、跟踪位置和具体状态值,从而提供可复现的解释。
英文摘要
This paper proposes an explainable digital twin for vulnerability detection in AArch64 machine code without access to source code. The digital twin reproduces the concrete execution of a program and preserves the state of registers, processor flags, memory, and live allocated blocks. Each instruction is transformed into a trace event containing the instruction name, operand values, and the post-instruction state. Vulnerabilities are represented as symbolic rules in Kleene algebra with tests: each rule specifies an event sequence and predicates over the machine state. This approach enables the detection of not only isolated unsafe instructions but also multi-step execution patterns. The rules are compiled into finite automata that scan the trace without using an SMT solver. The experimental evaluation covers three CWE classes: integer overflow (CWE-190), null pointer dereference (CWE-476), and heap buffer overflow (CWE-122). The system detected all three predefined vulnerabilities and produced no report on the safe trace. Each detection result includes the triggered rule, the trace position, and the concrete state values, thereby providing a reproducible explanation.