发表机构
IBM Research(IBM研究院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出BUGSTONE-E2E框架,从CVE修复提交中挖掘规则,经漏斗形流程检测漏洞,用19325个高严重性CVE验证,在14个程序中发现644个漏洞,实现将CVE历史转化为可执行的漏洞检测修复工作流。
AI 中文摘要
公开漏洞数据库收集了已知软件漏洞的丰富信息,包括其弱点类型、受影响组件和相关补丁。修复提交提供了消除这些漏洞的确切代码变更。虽然这些记录捕捉了原始代码不安全的原因,但它们主要是为人工检查而记录的,而非用于自动复用。因此,相同的不安全状况可能仍存在于代码的其他地方,而没有已知的通告,使得大部分此类检测知识未被利用。我们提出了BUGSTONE-E2E,这是一个将漏洞历史转化为可执行检测规则并验证其发现的框架。首先,BUGSTONE-E2E从经过验证的修复提交中挖掘可复用规则,捕获扫描锚点、修复语义和CVE来源,并按CWE和语言进行组织。其次,检测遵循漏斗形流程:早期阶段使用轻量级分析处理大量候选,后期阶段对缩小的目标集应用越来越强大且昂贵的模型。具体而言,BUGSTONE-E2E首先使用Tree-sitter枚举与规则锚点匹配的调用站点,然后在不调用LLM的情况下使用轻量级启发式方法去除良性站点。接下来,基于LLM的智能体在规则的引导下检查剩余候选。在此次检查之后,系统对幸存的候选重新分类并构建运行时验证,然后生成通过双向差分测试验证的范围检查补丁。使用2022年至2026年的19325个高严重性CVE,BUGSTONE-E2E识别出2710个修复提交,并构建了涵盖56个CWE家族的1033条检测规则,打包为172个技能。当应用于14个程序时,它为644个发现提供了运行时证据。这些结果表明,CVE历史可以转化为可执行工作流,将过去的漏洞转化为可复现的检测和修复。
英文摘要
Public vulnerability databases collect rich information about known software flaws, including their weakness types, affected components, and related patches. Fixing commits provide the exact code changes that removed these flaws. While these records capture why the original code was unsafe, they are documented mainly for human inspection rather than automated reuse. Consequently, the same unsafe conditions may still exist elsewhere in code without a known advisory, leaving much of this detection knowledge unused. We present BUGSTONE-E2E, a framework that transforms vulnerability history into executable detection rules and validates their findings. First, BUGSTONE-E2E mines reusable rules from verified fixing commits, capturing scan anchors, fix semantics, and CVE provenance and organizing them by CWE and language. Second, detection follows a funnel-shaped pipeline: early stages process a large pool of candidates using lightweight analysis, while later stages apply increasingly capable and expensive models to a shrinking set of targets. Specifically, BUGSTONE-E2E first enumerates call sites matching rule anchors using Tree-sitter, then removes benign sites using lightweight heuristics without LLM calls. Next, LLM-based agents inspect the remaining candidates guided by the rule. Following this inspection, the system re-triages surviving candidates and builds runtime verifications, then generates scope-checked patches validated via two-sided differential tests. Using 19,325 high-severity CVEs from 2022 to 2026, BUGSTONE-E2E identifies 2,710 fixing commits and constructs 1,033 detection rules across 56 CWE families, packaged into 172 skills. When applied across 14 programs, it produced runtime evidence for 644 findings. These results demonstrate that CVE history can be turned into an executable workflow, transforming past vulnerabilities into reproducible detection and repair.