发表机构
National University of Defense Technology; Clouditera(国防科技大学; 云迹科技)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对Linux内核漏洞利用策略与具体操作的概念鸿沟,提出多智能体框架PrimSynth,可发现、验证并合成漏洞利用原语,在16个真实CVE上取得100%原语匹配率及82.4%、61.3%的策略合成率。
AI 中文摘要
Linux内核漏洞对下游系统至关重要。尽管针对自动化内核漏洞利用的研究已十分广泛,但抽象漏洞利用策略与具体技术操作之间的概念鸿沟仍是一项核心挑战。为填补这一鸿沟,本文提出了一种系统表征方法,从逻辑能力到可验证效应,形式化了六类漏洞利用原语。随后,本文提出了一种扩展的漏洞利用策略表示方法,该方法将原语升级策略与原语路径代码合成规则相结合,这些规则管控对象约束、时间顺序、环境前提条件和验证约束。基于此基础,本文提出了PrimSynth,这是一个多智能体框架,通过协调智能体封装上述表示,用于发现、验证和合成Linux内核内存损坏漏洞的漏洞利用原语。这些智能体在迭代闭环中运行,直到找到有效原语,利用验证信号作为可利用状态转换的证据,为原语合成决策提供依据。本文还提出了一种基于漏洞导向执行和可重启验证环境的原语提取与验证自动化方法。在涵盖5种漏洞类型的16个真实Linux内核CVE上对PrimSynth进行评估,实验结果表明,PrimSynth实现了可靠的原语提取,保持100%的原语匹配率;对于原语合成,当有公开PoC时,PrimSynth成功合成多原语利用链,策略合成率(SSR)达82.4%,若无原语假设引导,SSR为61.3%。
英文摘要
Linux kernel vulnerabilities are critical to downstream systems. Despite extensive research on automated kernel exploitation, a fundamental challenge remains the conceptual gap between abstract exploit strategies and concrete technical operations. To fill this gap, this paper introduces a systematic characterization that formalizes six classes of exploit primitives from logical capability to validatable effect. Then, an extended exploit strategy representation is proposed, which couples primitive upgrading strategies with primitive path code synthesis rules governing object constraints, temporal sequencing, environment prerequisites, and validation constraints. Building upon this foundation, this paper presents \textsc{PrimSynth}, a multi-agent framework that encapsulates these representations through coordinated agents to discover, validate, and synthesize exploit primitives for memory corruption vulnerabilities in the Linux kernel. These agents operate in an iterative closed loop until valid primitives are found, leveraging validation signals as evidence of exploitable state transitions to ground primitive synthesis decisions. An automated method for extracting and validating primitives is also proposed based on vulnerability-directed execution and a rebootable validation environment. \textsc{PrimSynth} is evaluated on 16 real-world Linux kernel CVEs spanning 5 vulnerability types. Experimental results show that PrimSynth achieves reliable primitive extraction, maintaining a 100% primitive match rate. For primitive synthesis, PrimSynth successfully synthesizes multi-primitive exploitation chains with 82.4% strategy synthesis rate (SSR) when the public PoC is available and a 61.3% SSR without the guidance of primitive hypotheses.