SearcharxivSearch

arXiv subjects

Shichao Lv

Publications and source records attributed to Shichao Lv.

8 recordsLinked to original sources

Fixseeker: An Empirical Driven Graph-based Approach for Detecting Silent Vulnerability Fixes in Open Source Software

Open source software vulnerabilities pose significant security risks to downstream applications. While vulnerability databases provide valuable information for mitigation, many security patches are released silently in new commits of OSS repositories without explicit indications of their security impact. This makes it challenging for software maintainers and users to detect and address these vulnerability fixes. There are a few approaches for detecting vulnerability-fixing commits (VFCs) but most of these approaches leverage commit messages, which would miss silent VFCs. On the other hand, there are some approaches for detecting silent VFCs based on code change patterns but they often fail to adequately characterize vulnerability fix patterns, thereby lacking effectiveness. For example, some approaches analyze each hunk in known VFCs, in isolation, to learn vulnerability fix patterns; but vulnerabiliy fixes are often associated with multiple hunks, in which cases correlations of code changes across those hunks are essential for characterizing the vulnerability fixes. To address these problems, we first conduct a large-scale empirical study on 11,900 VFCs across six programming languages, in which we found that over 70% of VFCs involve multiple hunks with various types of correlations. Based on our findings, we propose Fixseeker, a graph-based approach that extracts the various correlations between code changes at the hunk level to detect silent vulnerability fixes. Our evaluation demonstrates that Fixseeker outperforms state-of-the-art approaches across multiple programming languages, achieving a high F1 score of 0.8404 on average in balanced datasets and consistently improving F1 score, AUC-ROC and AUC-PR scores by 32.40%, 1.55% and 8.24% on imbalanced datasets. Our evaluation also indicates the generality of Fixseeker across different repository sizes and commit complexities.

cs.SE

Towards Reliable LLM-Driven Fuzz Testing: Vision and Road Ahead

Fuzz testing is a crucial component of software security assessment, yet its effectiveness heavily relies on valid fuzz drivers and diverse seed inputs. Recent advancements in Large Language Models (LLMs) offer transformative potential for automating fuzz testing (LLM4Fuzz), particularly in generating drivers and seeds. However, current LLM4Fuzz solutions face critical reliability challenges, including low driver validity rates and seed quality trade-offs, hindering their practical adoption. This paper aims to examine the reliability bottlenecks of LLM-driven fuzzing and explores potential research directions to address these limitations. It begins with an overview of the current development of LLM4SE and emphasizes the necessity for developing reliable LLM4Fuzz solutions. Following this, the paper envisions a vision where reliable LLM4Fuzz transforms the landscape of software testing and security for industry, software development practitioners, and economic accessibility. It then outlines a road ahead for future research, identifying key challenges and offering specific suggestions for the researchers to consider. This work strives to spark innovation in the field, positioning reliable LLM4Fuzz as a fundamental component of modern software testing.

cs.SE

HoneyGPT: Breaking the Trilemma in Terminal Honeypots with Large Language Model

Honeypots, as a strategic cyber-deception mechanism designed to emulate authentic interactions and bait unauthorized entities, often struggle with balancing flexibility, interaction depth, and deception. They typically fail to adapt to evolving attacker tactics, with limited engagement and information gathering. Fortunately, the emergent capabilities of large language models and innovative prompt-based engineering offer a transformative shift in honeypot technologies. This paper introduces HoneyGPT, a pioneering shell honeypot architecture based on ChatGPT, characterized by its cost-effectiveness and proactive engagement. In particular, we propose a structured prompt engineering framework that incorporates chain-of-thought tactics to improve long-term memory and robust security analytics, enhancing deception and engagement. Our evaluation of HoneyGPT comprises a baseline comparison based on a collected dataset and a three-month field evaluation. The baseline comparison demonstrates HoneyGPT's remarkable ability to strike a balance among flexibility, interaction depth, and deceptive capability. The field evaluation further validates HoneyGPT's superior performance in engaging attackers more deeply and capturing a wider array of novel attack vectors.

cs.CR

VERCATION: Precise Vulnerable Open-source Software Version Identification based on Static Analysis and LLM

Open-source software (OSS) has experienced a surge in popularity, attributed to its collaborative development model and cost-effective nature. However, the adoption of specific software versions in development projects may introduce security risks when these versions bring along vulnerabilities. Current methods of identifying vulnerable versions typically analyze and extract the code features involved in vulnerability patches using static analysis with pre-defined rules. They then use code clone detection to identify the vulnerable versions. These methods are hindered by imprecision due to (1) the exclusion of vulnerability-irrelevant code in the analysis and (2) the inadequacy of code clone detection. This paper presents VERCATION, an approach designed to identify vulnerable versions of OSS written in C/C++. VERCATION combines program slicing with a Large Language Model (LLM) to identify vulnerability-relevant code from vulnerability patches. It then backtracks historical commits to gather previous modifications of identified vulnerability-relevant code. We propose code clone detection based on expanded and normalized ASTs to compare the differences between pre-modification and post-modification code, thereby locating the vulnerability-introducing commit (vic) and enabling the identification of the vulnerable versions between the vulnerability-fixing commit and the vic. We curate a dataset linking 122 OSS vulnerabilities and 1,211 versions to evaluate VERCATION. On this dataset, our approach achieves an F1 score of 93.1%, outperforming current state-of-the-art methods. More importantly, VERCATION detected 202 incorrect vulnerable OSS versions in NVD reports.

cs.SE

An Approach to Mismatched Disturbance Rejection Control for Continuous-Time Uncontrollable Systems

This paper focuses on optimal mismatched disturbance rejection control for linear continuoustime uncontrollable systems. Different from previous studies, by introducing a new quadratic performance index to transform the mismatched disturbance rejection control into a linear quadratic tracking problem, the regulated state can track a reference trajectory and minimize the influence of disturbance. The necessary and sufficient conditions for the solvability and the disturbance rejection controller are obtained by solving a forward-backward differential equation over a finite horizon. A sufficient condition for system stability is obtained over an infinite horizon under detectable condition. This paper details our novel approach for transforming disturbance rejection into a linear quadratic tracking problem. The effectiveness of the proposed method is provided with two examples to demonstrate.

math.OC

An Approach to Mismatched Disturbance Rejection Control for Uncontrollable Systems

This study focuses on the problem of optimal mismatched disturbance rejection control for uncontrollable linear discrete-time systems. In contrast to previous studies, by introducing a quadratic performance index such that the regulated state can track a reference trajectory and minimize the effects of disturbances, mismatched disturbance rejection control is transformed into a linear quadratic tracking problem. The necessary and sufficient conditions for the solvability of this problem over a finite horizon and a disturbance rejection controller are derived by solving a forward-backward difference equation. In the case of an infinite horizon, a sufficient condition for the stabilization of the system is obtained under the detectable condition. This paper details our novel approach to disturbance rejection. Four examples are provided to demonstrate the effectiveness of the proposed method.

math.OC

Mismatched Disturbance Rejection Control for Second-Order Discrete-Time Systems

This paper is concerned with mismatched disturbance rejection control for the second-order discrete-time systems.Different from previous work, the controllability of the system is applied to design the disturbance compensation gain, which does not require any coordinate transformations. Via this new idea, it is shown that disturbance in the regulated output is immediately and directly compensated in the case that the disturbance is known. When the disturbance is unknown, an extra generalized extended state observer is applied to design the controller. Two examples are given to show the effectiveness of the proposed methods. Numerical simulation shows that the designed controller has excellent disturbance rejection effect when the disturbance is known. The example with respect to the permanent-magnet direct current motor illustrates that the proposed control method for unknown disturbance rejection is effective.

math.OC

Performance Analysis of Low-Interference N-Continuous OFDM

The low-interference N-continuous orthogonal frequency division multiplexing (NC-OFDM) system [25], [26] is investigated in terms of power spectrum density (PSD) and bit error rate (BER), to prove and quantify its advantages over traditional NC-OFDM. The PSD and BER performances of the low-interference scheme are analyzed and compared under the parameters of the highest derivative order (HDO) and the length of the smooth signal. In the context of PSD, different from one discontinuous point per NC-OFDM symbol in [25], the sidelobe suppression performance is evaluated upon considering two discontinuous points due to the finite continuity of the smooth signal and its higher-order derivatives. It was shown that with an increased HDO and an increased length of the smooth signal, a more rapid sidelobe decaying is achieved, for the significant continuity improvement of the OFDM signal and its higher-order derivatives. However, our PSD analysis also shows that if the length of the smooth signal is set inappropriately, the performance may be degraded, even if the HDO is large. Furthermore, it was shown in the error performance analysis that under the assumptions of perfect and imperfect synchronization, the low-interference scheme incurs small BER performance degradation for a short length of the smooth signal or a small HDO as opposed to conventional NC-OFDM. Based on analysis and simulation results, the trade-offs between sidelobe suppression and BER are studied with the above two parameters.

cs.IT