arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.39783cs.SE

COMPASS:利用大语言模型预测漏洞多补丁关系

COMPASS: Predicting the Relationship of Multiple Patches for Vulnerabilities with LLMs

Yi Song, Dongchen Xie, Xiaoyuan Xie, He Zhang, Lin Xu, Chunying Zhou, Zhi Jin

首次发表
浏览论文内容

中文总结 AI 辅助

针对漏洞多补丁关系复杂导致下游采用困难的问题,提出COMPASS方法,利用大语言模型四阶段流水线预测补丁关系,在300个CVE基准上平均超越最先进方法85.04%。

中文摘要 AI 辅助

现代软件高度依赖代码复用,因此上游漏洞修复不会自动传播到下游代码库。下游维护者必须手动采用补丁以消除已知风险。在实践中,单个漏洞通常对应多个补丁,这极大地复杂化了下游补丁的采用过程,因为不同的补丁关系意味着不同的采用策略。为应对这一挑战,我们首先手动检查了现实世界中约1000个大规模多补丁漏洞,并采访了经验丰富的开发者,总结出六种典型的补丁关系类型,即合并、镜像、更优解决方案、修复之修复、协作和分离。基于这些观察,我们提出COMPASS,一种利用大语言模型自动预测多个漏洞补丁关系的方法。给定一个CVE作为输入,COMPASS遵循四阶段流水线:(i)识别补丁组并预扫描显式关系,(ii)执行单个补丁分析,(iii)通过层级引导提示推断关系实例,以及(iv)验证推断结果的完整性和一致性。作为输出,COMPASS报告补丁组内的预测关系,并将其可视化为关系图。我们在包含300个多补丁CVE的基准上评估COMPASS,并与主流基于学习和基于大语言模型的基线进行比较。结果表明,我们的方法实现了强大且一致的预测效果,平均比最先进方法高出85.04%。我们公开发布了一个在线查询网站,以支持社区复用补丁关系知识:此https URL。

英文摘要

Modern software heavily relies on code reuse, so upstream vulnerability fixes do not automatically propagate to downstream codebases. Downstream maintainers must manually adopt patches to eliminate known risks. In practice, a single vulnerability often corresponds to multiple patches, which greatly complicates downstream patch adoption because different patch relationships imply different adoption strategies. To address this challenge, we first manually inspect large-scale multi-patch vulnerabilities (about 1K) in the real world and interview experienced developers, summarizing six typical types of patch relationships, i.e., Merge, Mirror, Better Solution, Fixing-of-Fixing, Collaboration, and Separation. Based on these observations, we propose COMPASS, an automated approach that predicts the relationships of multiple vulnerability patches with large language models. Given a CVE as input, COMPASS follows a four-phase pipeline that (i) identifies the patch group and pre-scans explicit relationships, (ii) performs individual patch analysis, (iii) infers relationship instances via a hierarchy-guided prompt, and (iv) validates completeness and consistency of the inferred results. As output, COMPASS reports the predicted relationships within the patch group and visualizes them as a relationship graph. We evaluate COMPASS on a benchmark of 300 multi-patch CVEs and compare it against mainstream learning-based and LLM baselines. Results show that our method achieves strong and consistent prediction effectiveness and outperforms SOTA by 85.04% on average. We publicly release an online querying website to support community reuse of patch relationships knowledge: https://patch-relation.com.

发表机构

  • School of Cyber Science and Engineering, Wuhan University(武汉大学网络安全学院)
  • School of Computer Science, Wuhan University(武汉大学计算机学院)

机构由 AI 辅助整理,请以论文原文为准。

↑