כתבה
arXiv cs.AI ·
ההיסטוריה היא המגלה
The History Is the Detector: Executing CVE Patch History, End-to-End
BUGSTONE-E2E הוא כלי לגילוי פגיעויות בתוכנה. הוא מנצל את ההיסטוריה של תיקוני CVE כדי ליצור כללים מבצעים לגילוי פגיעויות. המערכת משתמשת בניתוח קל משקל ובמודלים מתקדמים כדי לזהות פגיעויות בקוד.
תקציר מקורי באנגליתarXiv:2609.05335v1 Announce Type: cross Abstract: Public vulnerability databases collect rich information about known software flaws, including their weakness types, affected components, and related patches. Fixing commits provide the exact code changes that removed these flaws. While these records capture why the original code was unsafe, they are documented mainly for human inspection rather than automated reuse. Consequently, the same unsafe conditions may still exist elsewhere in code without a known advisory, leaving much of this detection knowledge unused. We present BUGSTONE-E2E, a framework that transforms vulnerability history into executable detection rules and validates their findings. First, BUGSTONE-E2E mines reusable rules from verified fixing commits, capturing scan anchors,
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית