Python导入作为执行边界:关于缺陷、漏洞与分析空白的实证研究
Python Import as an Execution Boundary: An Empirical Study of Bugs, Vulnerabilities, and Analysis Gaps
浏览论文内容
中文总结 AI 辅助
本研究通过ImportMine实证分析Python导入执行代码引发的缺陷与漏洞,发现多数初始化激活问题导致执行中断或高危漏洞,并构建了覆盖11种缺陷类型的基准ImportVulBench。
中文摘要 AI 辅助
Python导入的作用不仅仅是解析依赖关系:它还会在模块和包初始化期间执行代码。这种行为可能在应用程序调用包API之前触发故障、加载动态或原生代码、访问资源或改变安全敏感状态。先前的工作研究了包选择、恶意包或包漏洞。我们提出了ImportMine,一项关于Python软件中与导入相关的缺陷和安全漏洞的研究。我们将安全公告与PyPI项目历史相结合,并使用源代码和补丁证据来确认导入如何激活案例、问题为何发生、开发者如何修复,以及需要哪些程序信息来解释该行为。我们保留了31个与导入相关的公告漏洞和38个应用程序数据边界案例,并确认了1,302个仓库中的1,429个项目历史缺陷。在初始化期间激活的项目历史缺陷中,97.6%会停止或中断正常执行。相比之下,20个初始化激活的公告漏洞中90.0%属于高危或严重级别。模块级代码和包初始化激活了98.3%的分析历史案例。动态加载不太常见,但其大多数案例执行安全敏感操作。我们还发现许多修复改变了导入何时变为活跃,而不是移除依赖。最后,我们构建了ImportVulBench,包含228对修复前和修复后的程序,覆盖所有11种缺陷类型。
英文摘要
Python import does more than resolve dependencies: it executes code during module and package initialization. This behavior can trigger failures, load dynamic or native code, access resources, or change security-sensitive state before an application calls a package API. Prior work studies package selection, malicious packages, or package vulnerabilities. We present ImportMine, a study of import-related bugs and security vulnerabilities in Python software. We combine security advisories with PyPI project histories and use source and patch evidence to confirm how import activates cases, why the problem occurs, how developers fix it, and what program information is needed to explain the behavior. We retain 31 import-related advisory vulnerabilities and 38 application-data boundary cases and confirm 1,429 project-history bugs across 1,302 repositories. Among the project-history bugs activated during initialization, 97.6% stop or disrupt normal execution. In contrast, 90.0% of the 20 initialization- activated advisory vulnerabilities are High or Critical. Module-level code and package initialization activate 98.3% of the analyzed history cases. Dynamic loading is much less common, but most of its cases perform security-sensitive actions. We also find that many fixes change when an import becomes active instead of removing the dependency. Finally, we derive ImportVulBench, 228 paired pre-fix and fixed programs covering all 11 bug types.
发表机构
- Utah State University(犹他州立大学)
机构由 AI 辅助整理,请以论文原文为准。