arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

代理系统中开源软件漏洞的安全效应表征

Characterizing Security Effects of OSS Vulnerabilities in Agent Systems

Yu Ji, Yang Wei, Yutao Hu, Haojun Zhao, Yueming Wu, Deqing Zou

arXiv 2610.05036首次发表:更新:

发表机构

Huazhong University of Science and Technology; Cyberspace Security University of China(华中科技大学; 中国网络安全大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过差异执行与运行时溯源,表征代理系统中开源漏洞的安全效应及其传播边界,并识别真实框架中的多个漏洞影响。

AI 中文摘要

软件代理在执行工具和与外部系统交互时,日益依赖开源组件。因此,这些依赖项中的安全缺陷可能不仅影响其所在的软件进程:其后果可以通过工具输出、代理状态以及随后暴露给模型的信息而传播。确定这种后果在特定执行中是否实际实现,以及其影响在代理系统内的何处终止,仍然具有挑战性。我们研究了已知的开源软件漏洞在作为代理工作流的一部分被利用时的行为。我们的研究揭示了安全相关后果在运行时各层中产生和传播的反复出现的模式。基于这些观察,我们利用漏洞感知的语义信息、漏洞软件与修正软件的差异执行以及跨多层的运行时溯源,来确定漏洞是否产生可观察的安全效应,并识别该效应仍表现出的最远层。我们的评估表明,该方法能够准确区分已实现的漏洞效应,并在多样化的漏洞场景集合中确定其表现边界。我们还将该分析应用于真实世界代理框架中记录的工作流,并发现了源自其开源软件依赖项中已知漏洞的多个安全效应。这些结果强调了根据漏洞在执行层面的后果而非仅凭漏洞存在来推理易受攻击依赖项的重要性。

英文摘要

Software agents increasingly depend on open-source components when executing tools and interacting with external systems. Security flaws in these dependencies may therefore influence more than the software process in which they occur: their consequences can be carried through tool outputs, agent state, and information subsequently exposed to the model. Determining whether such a consequence is actually realized in a particular execution, and where its influence stops within the agent system, remains challenging. We investigate how known OSS vulnerabilities behave when exercised as part of agent workflows. Our study reveals recurring patterns in the way security-relevant consequences emerge and propagate across runtime layers. Building on these observations, we use vulnerability-aware semantic information, differential executions of vulnerable and corrected software, and runtime provenance spanning multiple layers to determine whether a vulnerability produces an observable security effect and to identify the furthest layer at which that effect remains manifested. Our evaluation shows that this approach can accurately distinguish realized vulnerability effects and determine their manifestation boundaries across a diverse collection of vulnerability scenarios. We additionally apply the analysis to documented workflows in a real-world agent framework and uncover multiple security effects originating from known vulnerabilities in its OSS dependencies. These results highlight the importance of reasoning about vulnerable dependencies in terms of their execution-level consequences rather than vulnerability presence alone.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑