Vulnerabilities often recur in software due to code reuse, particularly with widely used third-party libraries. Detecting such vulnerabilities, including 1-day and N-day types, is crucial for cybersecurity. Current methods struggle with poor performance as they focus on detecting patch existence rather than actual vulnerabilities and derive signatures directly from binary code. We propose VulMatch, which generates precise vulnerability signatures by analyzing both source and binary code. Our method outperforms existing tools like Asm2vec and Palmtree and provides better explainability in detection. Tested on over 1,000 vulnerabilities across seven open-source projects and commercial firmware, VulMatch demonstrates superior fine-grained detection capabilities.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

VulMatch: Binary-Level Vulnerability Detection Through Signature

  • Zian Liu,
  • Shigang Liu,
  • Lei Pan,
  • Chao Chen,
  • Ejaz Ahmed,
  • Jun Zhang,
  • Dongxi Liu

摘要

Vulnerabilities often recur in software due to code reuse, particularly with widely used third-party libraries. Detecting such vulnerabilities, including 1-day and N-day types, is crucial for cybersecurity. Current methods struggle with poor performance as they focus on detecting patch existence rather than actual vulnerabilities and derive signatures directly from binary code. We propose VulMatch, which generates precise vulnerability signatures by analyzing both source and binary code. Our method outperforms existing tools like Asm2vec and Palmtree and provides better explainability in detection. Tested on over 1,000 vulnerabilities across seven open-source projects and commercial firmware, VulMatch demonstrates superior fine-grained detection capabilities.