LLM-Powered Static Binary Taint Analysis
Puzhuo Liu, C. P. Sun, Yaowen Zheng, Xuan Feng, Chuan Qin, Y. F. Wang, Zhenyang Xu, Zhi Li 等 11 位
Tsinghua University University of Waterloo Institute of Information Engineering University of Chinese Academy of Sciences
阅读操作
确认中在文库中上传 PDF 后可生成中文音频讲解。
摘要与影响
This article proposes LATTE , the first static binary taint analysis that is powered by a large language model (LLM). LATTE is superior to the state of the art (e.g., Emtaint, Arbiter, Karonte) in three aspects. First, LATTE is fully automated while prior static binary taint analyzers need rely on human expertise to manually customize taint propagation rules and vulnerability inspection rules. Second, LATTE is significantly effective in vulnerability detection, demonstrated by our comprehensive evaluations. For example, LATTE has found 37 new bugs in real-world firmware, which the baselines failed to find. Moreover, 10 of them have been assigned CVE numbers. Lastly, LATTE incurs remarkably low engineering cost, making it a cost-efficient and scalable solution for security researchers and practitioners. We strongly believe that LATTE opens up a new direction to harness the recent advance in LLMs to improve vulnerability analysis for binary programs.
逐年被引趋势
关键指标
同类平均 = 1
同领域 · 同年份 · 同类型
Google Scholar 与 OpenAlex 的被引统计范围不同,数值存在差异属正常。
AI 辅助阅读
依据:摘要
可就本文提问;依据不足时会说明。
学术脉络
学科主题
计算机 / AIWeb Application Security Vulnerabilities
Advanced Malware Detection Techniques · Security and Verification in Computing
参考文献 63
此处列出前 3 条
引用本文 28
按被引量排序,此处列出前 3 条