节点文献

云边端内核竞态漏洞大模型分析方法研究

Research on Large Model Analysis Methods for Kernel Race Vulnerabilities in Cloud-Edge-Device Scenarios

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 陈平; 骆明宇;

【Author】 CHEN Ping;LUO Mingyu;Institute of Big Data, Fudan University;School of Computer Science, Fudan University;

【通讯作者】 骆明宇;

【机构】 复旦大学大数据研究院; 复旦大学计算机科学技术学院;

【摘要】 随着云边端场景的广泛应用,操作系统内核竞态条件检测面临新的挑战,其复杂性日益提升。针对这一问题,文章提出一种基于大语言模型的内核竞态条件分析方法 Log Fuzz。该方法通过知识注入机制,实现对系统调用依赖关系的动态学习与精准分析,有效缓解云边端环境下内核漏洞分析的难题。研究首先利用崩溃日志进行系统调用模式提取与分析,解决传统方法在复杂依赖关系建模中的局限性。在此基础上,引入大语言模型的领域知识,通过参数高效微调框架深度挖掘系统调用的语义与语法特征,指导模糊测试。实验结果表明,在Linux内核测试中,文章所提方法在18 h后的分支覆盖率较传统方法提升3.31%,并成功触发7个系统崩溃。该方法有助于提升系统安全,为云边端内核竞态条件检测提供一种技术路径。

【Abstract】 With the widespread application of cloud-edge-device scenarios, kernel race condition detection in operating systems faces new challenges, and its complexity is increasing. To address this issue, this paper proposed a kernel race condition analysis method called LogFuzz based on large language model. This method achieved dynamic learning and precise analysis of system call dependencies through a knowledge injection mechanism,effectively alleviating the difficulties in kernel vulnerability analysis in cloud-edge-device environments. The research first utilized crash logs for system call pattern extraction and analysis, addressing the limitations of traditional methods in modeling complex dependencies.On this basis, domain knowledge from large language models was introduced, and system call semantics and syntactic features are deeply mined through a parameter-efficient finetuning framework to guide fuzz testing. Experimental results show that the proposed method,in Linux kernel testing, improved branch coverage by 3.31% compared to traditional methods after 18 hours and successfully triggered 7 system crashes. The method proposed in this paper provides a new technical path for kernel race condition detection in cloud-edge-device scenarios and is of great significance for enhancing system security.

【基金】 国家重点研发计划[2022YFB3104300]
  • 【文献出处】 信息网络安全 ,Netinfo Security , 编辑部邮箱 ,2025年07期
  • 【分类号】TP309;TP316
  • 【下载频次】18
节点文献中: 

本文链接的文献网络图示:

本文的引文网络