AI 中文总结
KEVGraph提出利用感知的依赖漏洞修复流水线,通过KEV感知的集合覆盖和ILP规划,优先消除主动利用漏洞,在npm、Maven和PyPI上显著优于CVSS优先排序。
AI 中文摘要
依赖扫描工具会暴露数百个漏洞,但并未提供利用感知的排序,导致从业者在没有原则性指导的情况下决定首先执行哪些升级。按CVSS严重性排序的主流做法与主动利用在结构上不匹配:在我们的npm语料库中,186个非KEV漏洞的CVSS评分高于8,全部排在三个CISA已知利用漏洞(KEV)列出的包之前,导致CVSS优先的工具将首次主动利用的修复推迟了17次升级操作。KEVGraph是一个八阶段流水线,将修复问题构建为KEV感知的集合覆盖问题:它从锁文件构建每个仓库的依赖图,将其与OSV和CISA KEV目录连接,并通过精确整数线性规划(ILP)或KEV感知的贪心算法生成最小基数的升级计划,该计划排序以尽早消除主动利用的漏洞。在924个真实世界npm仓库(1,046个漏洞,5个KEV列出的)上评估,ILP规划器实现了AUCCKEV = 0.997,而随机基线均值为0.663(95%置信区间[0.519, 0.831],n = 30),在计划步骤1解决了第一个KEV漏洞,且仅需417次升级操作,比随机均值495.4少15.9%。CVSS优先和Dependabot风格的排序被严格支配:它们将第一个KEV修复推迟到步骤18,同时需要更多操作(分别为419和421)。该框架具有泛化性:Maven(1,200个仓库)实现AUCCKEV = 0.988,而随机均值为0.486;PyPI(300个仓库)实现AUCCKEV = 1.000。每个计划都附带机器可验证的证书,支持在CISA BOD 22-01下进行自动化合规性验证。
英文摘要
Dependency scanning tools surface hundreds of vulnerabilities but provide no exploitation-aware ordering, leaving practitioners to decide which upgrades to perform first with no principled guidance. The dominant practice, ordering by CVSS severity, is structurally misaligned with active exploitation: in our npm corpus, 186 non-KEV vulnerabilities carry CVSS scores greater than 8, all outranking three CISA Known Exploited Vulnerability (KEV)-listed packages and causing CVSS-first tools to defer the first actively exploited fix by 17 upgrade actions. KEVGraph is an eight-stage pipeline that frames remediation as a KEV-aware set-cover problem: it constructs per-repository dependency graphs from lockfiles, joins them against OSV and the CISA KEV catalogue, and produces a minimum-cardinality upgrade plan ordered to eliminate actively exploited vulnerabilities as early as possible via exact Integer Linear Programming (ILP) or a KEV-aware greedy algorithm. Evaluated on 924 real-world npm repositories (1,046 vulnerabilities, 5 KEV-listed), the ILP planner achieves AUCCKEV = 0.997 versus a random-baseline mean of 0.663 (95 percent CI [0.519, 0.831], n = 30), resolves the first KEV vulnerability at plan step 1, and requires only 417 upgrade actions, 15.9 percent fewer than the random mean of 495.4. CVSS-first and Dependabot-style ordering are strictly dominated: they defer the first KEV fix to step 18 while requiring more actions (419 and 421, respectively). The framework generalises: Maven (1,200 repos) achieves AUCCKEV = 0.988 versus random mean 0.486; PyPI (300 repos) achieves AUCCKEV = 1.000. Each plan is accompanied by a machine-verifiable certificate enabling automated compliance verification under CISA BOD 22-01.
Comments10 pages, 6 figures