发表机构
University of New Hampshire(新罕布什尔大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究将自动化程序修复扩展至固件层,通过挖掘EDK II固件仓库的修复模板,构建4个定位器,在CVE漏洞修复上实现高召回率,为硬件到固件的统一正确性生命周期提供支撑。
AI 中文摘要
自动化程序修复(APR)研究目前局限于设计阶段,现有技术会在芯片量产前对RTL或HLS设计中的漏洞进行定位与修复。一旦硅片流片后出现硬件漏洞,修复补丁必须手动生成:现有自动化技术仅能处理补丁部署,无法实现补丁合成。本研究探讨将原本为RTL修复开发的、基于字典引导的“定位-合成-验证”APR方法扩展到固件层的可行性。研究使用自动化提交聚类挖掘器,在不依赖已知CVE标识符的情况下,从EDK II(UEFI)固件仓库的完整提交历史中挖掘出重复出现的修复模板,成功恢复全部3个已知CVE修复案例,并发现2个额外的候选漏洞家族。基于真实修复证据,本研究构建了4个独立定位器:C语言中缺失的推测屏障(对应CVE-2017-5753,即Spectre v1)、C语言中数组写入前缺失的边界检查(对应某解压库CVE)、x86汇编中缺失的返回栈缓冲区填充(对应CVE-2017-5715),以及Hand-Off Block创建代码中缺失的整数溢出防护(由挖掘器自行发现)。这4个定位器均达到100%召回率;精度方面,C语言相关家族为2.1%-15.5%,汇编与HOB家族则为100%。对C家族误报的根本原因分析显示,77%-90%的误报源于2种过程内原因,过程间别名分析缺口的实测值为15%-20%,而非估算值。保留测试集验证表明,Spectre v1定位在未见过的文件上仍保持100%召回率;第5个独立构建的字典条目(CVE-2018-3630)显示该方法可低成本扩展到新漏洞特征;而朴素句法基线的最高召回率为14%,本研究的检测器则达到100%召回率。本研究将这些结果置于从硬件到固件的统一正确性生命周期的更广泛研究议程框架下。
英文摘要
Automated program repair (APR) research has been constrained to design time. Current techniques localize and fix bugs in RTL or HLS designs before a chip reaches production. Once a hardware vulnerability surfaces post-silicon, the patch must be manually generated: existing automation addresses patch deployment but not patch synthesis. We study the feasibility of extending a dictionary-guided, localize-synthesize-validate APR methodology originally developed for RTL repair to this firmware layer. An automated commit-clustering miner surfaces recurring fix templates across the EDK II (UEFI) firmware repository's full commit history without depending on known CVE identifiers, recovering all three known CVE-fix campaigns and surfacing two additional candidate bug families. Grounded in real fix evidence, we build four independent localizers: missing speculation barriers in C (CVE-2017-5753, Spectre v1), missing bounds checks before array writes in C (a decompression library CVE), missing Return Stack Buffer stuffing in x86 assembly (CVE-2017-5715), and missing integer-overflow guards in Hand-Off Block creation code (surfaced by the miner itself). All four achieve 100% recall; precision ranges from 2.1-15.5% on the C families to 100% on the assembly and HOB families. Root-cause analysis of the C-family false positives attributes 77-90% to two intra-procedural causes, isolating the inter-procedural alias-analysis gap as a measured 15-20% rather than an estimate. A held-out test confirms Spectre v1 localization holds at 100% recall on unseen files; a fifth, independently built dictionary entry (CVE-2018-3630) shows the methodology extends to a new bug signature at low cost; and a naive syntactic baseline recalls at most 14% where our detector recalls 100%. We frame these results within a broader research agenda for a unified hardware-to-firmware correctness lifecycle.