POLYFLOW:用于静态跨语言信息流分析的神经符号框架
POLYFLOW: A Neuro-Symbolic Framework for Static Cross-Language Information Flow Analysis
- Washington State University(华盛顿州立大学)
- University at Buffalo, SUNY(纽约州立大学布法罗分校)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
PolyFlow是结合LLM与静态分析的跨语言信息流分析神经符号框架,在多语言系统实验中表现优于基线,可发现未知跨语言漏洞。
AI中文摘要:
现代软件系统通常由多种相互交互的编程语言构建而成,这种构建方式会在复杂信息流中引入额外的、往往难以察觉的漏洞,这些漏洞源于语言交互。现有静态分析工具受不同语言的异构语义阻碍,而动态方法则受限于(可用和/或生成的)测试输入的覆盖范围有限。在本文中,我们开发了PolyFlow,这是一种用于跨语言边界静态推理信息流的神经符号框架,协同结合了大型语言模型(LLM)和静态分析。在给定多语言系统控制流表示的驱动下,PolyFlow利用LLM识别因具有挑战性的语言特征而产生的隐式流事实,从而增强基础表示,随后在系统中传播数据流。它通过对LLM进行精心指导(例如静态分析引导的范围界定、上下文管理和事实核查),以及采用多LLM专家小组进行协商验证,解决了LLM的固有障碍(例如token限制和幻觉)。我们在真实世界的Python-C和Java-C系统上进行的实验表明,PolyFlow具有成本效益,且优于各种最先进的基线,能够揭示所有基线都遗漏的此前未知的跨语言漏洞。
英文摘要:
Modern software systems are commonly constructed in multiple, interacting programming languages. This construction leads to additional, often stealthy vulnerabilities buried in complex information flow due to language interactions. Existing static analyzers are impeded by the heterogeneous semantics of different languages, whereas dynamic approaches suffer from the limited coverage of (available and/or generated) test inputs. In this paper, we develop PolyFlow, a neural-symbolic framework for statically reasoning about information flow across language boundaries, combining large language models (LLMs) and static analysis synergistically. Governed by the control-flow representation of a given multi-language system, PolyFlow leverages LLMs to identify implicit flow facts due to challenging language features, hence augmenting the base representation and then propagating data flow through the system. It tackles inherent barriers (e.g., token limit and hallucination) of LLMs by putting them under careful guidance (e.g., static-analysis-guided scoping, context management, and fact checking), along with a multi-LLM expert panel for negotiated validation. Our experiments on real-world Python-C and Java-C systems show that PolyFlow is cost-effective and superior to various kinds of state-of-the-art baselines, revealing previously unknown cross-language vulnerabilities that are missed by all the baselines.