RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    스트립 바이너리에서 보안 취약점 탐지를 위한 LLM 기반 프레임워크 = LLM-Based Detection Framework of Vulnerabilities in Stripped Binaries

    한글로보기

    https://www.riss.kr/link?id=A110179216

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Stripped binaries have debugging information removed, making it difficult to directly apply existing source code-based static analysis techniques. To address this challenge, this paper proposes a framework for detecting memory vulnerabilities in stripped binaries using large language models. The proposed framework decompiles stripped binaries into pseudocode using Ghidra, then extracts data flow paths from memory deallocation functions to allocation functions through backward slicing, using deallocation functions as reference points. Attention markers are inserted at memory allocation and deallocation points in the extracted code to guide the LLM to focus on critical locations during vulnerability detection analysis. Finally, vulnerability type-specific prompts are generated to classify vulnerable bug classes and patterns through few-shot inference without fine-tuning. Experimental results demonstrate an overall accuracy of 83.6% on 1,996 samples, proving the feasibility of detecting CWE-415(Double Free) and CWE-416(Use-After-Free) vulnerabilities in stripped binaries through prompt engineering without model training.
    번역하기

    Stripped binaries have debugging information removed, making it difficult to directly apply existing source code-based static analysis techniques. To address this challenge, this paper proposes a framework for detecting memory vulnerabilities in strip...

    Stripped binaries have debugging information removed, making it difficult to directly apply existing source code-based static analysis techniques. To address this challenge, this paper proposes a framework for detecting memory vulnerabilities in stripped binaries using large language models. The proposed framework decompiles stripped binaries into pseudocode using Ghidra, then extracts data flow paths from memory deallocation functions to allocation functions through backward slicing, using deallocation functions as reference points. Attention markers are inserted at memory allocation and deallocation points in the extracted code to guide the LLM to focus on critical locations during vulnerability detection analysis. Finally, vulnerability type-specific prompts are generated to classify vulnerable bug classes and patterns through few-shot inference without fine-tuning. Experimental results demonstrate an overall accuracy of 83.6% on 1,996 samples, proving the feasibility of detecting CWE-415(Double Free) and CWE-416(Use-After-Free) vulnerabilities in stripped binaries through prompt engineering without model training.

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼