arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.23755cs.SE

SPIDER4TianoCore:为TianoCore UEFI固件开发生态系统增强补丁传播功能

SPIDER4TianoCore: Enhancing Patch-Propagation for the TianoCore UEFI Firmware Development Ecosystem

Laura Baird, Devin Haggitt, Terrance E. Boult, Aravind Machiry, Armin Moin

首次发表
浏览论文内容

中文总结 AI 辅助

该研究提出SPIDER4TianoCore工具,为TianoCore UEFI固件供应链提供补丁状态证据,经评估其在20个目标/CVE配对及2个CVE上表现出良好分类能力,可生成可靠补丁相关证据。

中文摘要 AI 辅助

我们提出并演示了SPIDER4TianoCore,这是一款打包的Python命令行工具,可为TianoCore/UEFI固件供应链提供集成阶段的补丁状态证据。给定上游补丁前和补丁后的配对以及准备好的下游目标,该工具会报告“易受攻击”、“已修补”、“不适用”或“不确定”,并提供支持证据供维护者审查。我们的工作灵感来自SPIDER的补丁传播框架,但SPIDER4TianoCore本身并不证明补丁传播是安全的。我们在来自8个公开下游EDK II仓库的20个准备好的目标/CVE配对以及2个CVE上评估了该引擎。分析器生成了10个高置信度的补丁前匹配项和4个高置信度的补丁后匹配项,对6个目标保守地弃权(不执行),相对于记录的手动补丁状态标签,没有做出自信的错误分类。这些初步结果证明了针对准备好的目标的可重复证据生成,而非一般下游准确性。

英文摘要

We propose and demonstrate SPIDER4TianoCore, a packaged Python command-line tool that provides integration-stage patch-status evidence for the TianoCore/UEFI firmware supply chain. Given an upstream pre-patch and post-patch pair and prepared downstream targets, the tool reports Vulnerable, Already Patched, Not Applicable, or Uncertain with supporting evidence for maintainer review. Our work is inspired by SPIDER's patch-propagation framing, but SPIDER4TianoCore does not itself prove that a patch is safe to propagate. We evaluate the engine on 20 prepared target/CVE pairs from eight public downstream EDK II repositories and two CVEs. The analyzers produce 10 high-confidence pre-patch matches and four high-confidence post-patch matches, conservatively abstain on six targets, and make no confidently wrong classifications relative to the recorded manual patch-state labels. These preliminary results demonstrate reproducible evidence generation for prepared targets rather than general downstream accuracy.

发表机构

  • University of Colorado Colorado Springs(科罗拉多大学科泉分校)
  • Purdue University(普渡大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑