发表机构
Xidian University(西安电子科技大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
TAILOR是一个类型与状态感知的多智能体框架,通过自适应执行路径和前置状态构建,在200个CVE数据集上分别复现59.24%的Web漏洞和44.19%的传统漏洞,提供可审计证据。
AI 中文摘要
日益增长的漏洞披露和广泛的软件复用增加了安全团队对可复现证据的需求,以诊断漏洞、验证补丁并构建回归测试。大规模生成此类证据需要自动化的端到端CVE复现。现有方法通常通过统一流水线处理不同的CVE,但运行时形式、触发接口和前置状态的差异对各个阶段施加了不同的执行要求,使得固定工作流难以适应多样化的复现需求。为解决这一问题,我们提出了TAILOR,一个类型与状态感知的多智能体框架,专门用于复杂漏洞复现。TAILOR将静态漏洞信息转换为可审计的复现证据,并将重建的环境和触发证据打包为复现工件。其第一级类型感知机制自适应地将每个漏洞匹配到执行路径。在Web路径内,其第二级状态感知机制在利用前构建所需的前置状态,将前置状态构建与核心漏洞触发解耦,并在利用和验证之间共享执行约束。我们构建了一个包含200个CVE的数据集,重点强调具有复杂执行要求的案例。TAILOR成功复现了59.24%的Web漏洞和44.19%的传统漏洞。进一步的消融实验表明,这两个控制级别分别缓解了执行路径不匹配和Web前置状态缺失的问题。总体而言,TAILOR拓宽了自动化CVE复现的覆盖范围,并为漏洞诊断和防御提供了可审计的证据。
英文摘要
Growing vulnerability disclosure and widespread software reuse increase security teams' need for reproducible evidence to diagnose vulnerabilities, validate patches, and build regression tests. Producing such evidence at scale requires automated end-to-end CVE reproduction. Existing methods typically process different CVEs through a uniform pipeline, but differences in runtime form, trigger interfaces, and prerequisite state impose different execution requirements on individual stages, making fixed workflows difficult to adapt to diverse reproduction needs. To address this problem, we present TAILOR, a type- and state-aware multi-agent framework specialized for complex vulnerability reproduction. TAILOR converts static vulnerability information into auditable reproduction evidence and packages reconstructed environments and trigger evidence into reproduction artifacts. Its first-level type-aware mechanism adaptively matches each vulnerability to an execution path. Within the Web path, its second-level state-aware mechanism constructs the required prerequisite state before exploitation, decouples prerequisite-state construction from core vulnerability triggering, and shares execution constraints across exploitation and verification. We construct a dataset of 200 CVEs with an emphasis on cases with complex execution requirements. TAILOR successfully reproduces 59.24\% of Web vulnerabilities and 44.19\% of traditional vulnerabilities. Further ablation experiments show that the two control levels respectively mitigate execution-path mismatch and missing Web prerequisite state. Overall, TAILOR broadens the coverage of automated CVE reproduction and provides auditable evidence for vulnerability diagnosis and defense.