arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

C到Rust的谬误:自动重构≠内存安全

C-to-Rust Fallacy: Automatic Refactoring != Memory Security

Hung-Mao Chen, Xu He, Bo Lu, Xiaokuan Zhang, Kun Sun

arXiv 2609.25682首次发表:更新:

发表机构

George Mason University; Visa Inc.(乔治梅森大学; 威士)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文实证评估四种C到Rust自动重构工具,发现多数生成代码存在编译失败、继承或新增内存漏洞,表明当前工具仅实现狭义内存安全而非全面内存安全。

AI 中文摘要

Rust已成为领先的系统编程语言,在不牺牲性能的前提下提供强大的内存和类型安全保证。这使其成为传统语言(如易受内存安全漏洞影响的C和C++)的有力替代品。然而,手动将C转换为Rust需要对Rust语言特性有深入的领域知识,这对开发者来说需要付出大量努力。为解决这一问题,用于自动C到Rust重构的工具旨在利用静态分析和大型语言模型(LLMs)生成安全的Rust代码。虽然这些工具声称通过减少不安全的Rust来实现安全,但其与提升安全性的相关性尚不明确。在本文中,我们对各种C到Rust重构方法的可靠性、安全性和正确性进行了全面的实证研究。具体而言,我们使用来自NIST Juliet测试套件的116个含内存安全漏洞的C程序数据集,评估了C2Rust-analyze、CROWN、C2SaferRust和FLOURINE。基于这些工具生成的464个Rust程序,我们的评估聚焦于三个关键方面:重构程序的编译正确性、缓解原始C漏洞的有效性,以及引入额外Rust漏洞的倾向。结果表明,342个Rust程序未能编译,177个Rust程序继承了原始C程序的内存安全漏洞,并引入了77个新的Rust漏洞。我们审视了工具设计背后的原理,并分析了各种重构方法中错误的根本原因。我们的发现表明,当前自动化重构工具提供了它们所定义的内存安全,但在采用时并未提供更广泛的内存安全。

英文摘要

Rust has emerged as the leading system programming language, offering strong memory and type safety guarantees without compromising performance. This positions it as a compelling alternative to traditional languages like C and C++, which are susceptible to memory security bugs. However, manually transforming C to Rust requires in-depth domain knowledge of the Rust language features, which requires significant effort for developers. To address this, tools for automatic C-to-Rust refactoring aim to generate safe Rust code leveraging static analysis and Large Language Models (LLMs). While these tools claim to achieve safety by reducing the unsafe Rust, the correlation with improving security is not clear. In this paper, we conduct a comprehensive empirical study on the reliability, safety, and correctness of various C-to-Rust refactoring methods. Specifically, we evaluate C2Rust-analyze, CROWN, C2SaferRust, and FLOURINE using a dataset of 116 C programs with memory security bugs from the NIST Juliet Test Suite. Based on 464 Rust programs generated by these tools, our evaluation focuses on three key aspects: the compilation correctness of the refactored programs, the effectiveness in mitigating original C bugs, and the tendency to introduce additional Rust bugs. The results indicate that 342 Rust programs fail to compile, 177 Rust programs inherit memory security bugs from the original C programs, and 77 new Rust bugs are introduced. We examine the rationale behind tool design and analyze the root cause of errors across various refactoring methods. Our findings indicate that current automated refactoring tools deliver memory safety as they define it, but not the broader memory security when adopting them.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑