SNIPTEST:针对漏洞验证的多级代码切片模糊测试
SNIPTEST: Fuzzing Multi-Level Code Slices for Validating Vulnerabilities
浏览论文内容
中文总结 AI 辅助
SNIPTEST是一种基于执行的警告分类框架,通过分层切片策略生成并模糊测试代码切片,在97个真实漏洞和97个误报的基准中取得良好效果,还识别出CVE-2025-11964。
中文摘要 AI 辅助
现代软件系统日益复杂,静态分析工具常通过发出警告来识别潜在易受攻击的代码,但这些警告往往需要人工检查以确认报告问题是否真实,导致该过程耗时且易出错。定向模糊测试已成为验证警告的强大自动化技术,但针对每个警告将其应用于整个项目在计算上不可行,通常需要数天执行才能实现代码覆盖率的增量提升。我们提出SNIPTEST,一种基于执行的警告分类框架,它生成并模糊测试以静态分析警告为中心的已编译代码切片。SNIPTEST不证明完整程序中的可利用性,而是提供关于警告在逐步扩展的切片执行上下文下如何表现的证据。它采用分层切片策略,围绕目标位置逐步扩展上下文,以更高精度验证潜在漏洞。我们在包含三个真实项目的97个真实漏洞和97个误报的基准上评估SNIPTEST:在97个已确认漏洞中,SNIPTEST通过在所有三个分析切片级别一致触发相应的漏洞预言机,为53个漏洞(占54.6%)生成可能的真阳性证据,其余案例不可达;在这些案例中,40.2%的案例中,它沿观察到的执行路径利用漏洞,匹配前三个栈帧。在97个已确认误报中,SNIPTEST通过到达警告但不触发漏洞预言机,为54个案例(占55.6%)生成可能的假阳性证据,而28个案例(占28.8%)被错误分类,其余案例未被触及。最后,我们通过识别CVE-2025-11964证明了SNIPTEST的实际相关性。
英文摘要
Modern software systems are increasingly complex, and static analysis tools are commonly used to identify potentially vulnerable code by issuing warnings. However, these warnings often require manual inspection to confirm whether the reported issues are real, making the process time-consuming and error-prone. Directed fuzzing has emerged as a powerful automated technique to validate the warnings. However, applying it to the entire project in response to each warning is computationally infeasible, often requiring days of execution to achieve only incremental improvements in code coverage. We present SNIPTEST, an execution-based warning triage framework that generates and fuzzes compiled code slices centered around static-analysis warnings. Rather than proving exploitability in the full program, SNIPTEST provides evidence about how a warning behaves under progressively expanded sliced execution contexts. It employs a layer-by-layer slicing strategy, incrementally expanding context around the target location to validate potential vulnerabilities with increasing precision. We evaluate SNIPTEST on a benchmark of 97 true vulnerabilities and 97 false alarms across three real-world projects. SNIPTEST produces Possible True Positive evidence for 53 of 97 confirmed vulnerabilities (54.6%) by triggering the corresponding bug oracle consistently across all three analyzed slice levels, while the remaining cases are unreachable. Particularly, in 40.2% of these cases, it exploits the vulnerability along the observed execution path, matching the top three stack frames. On the 97 confirmed false alarms, SNIPTEST produces Possible False Positive evidence for 54 cases (55.6%) by reaching the warning without triggering the bug oracle, but misclassifies 28 cases (28.8%),and the remaining cases are unreached. Finally, we demonstrate the practical relevance of SNIPTEST by identifying CVE-2025-11964.