跳到主要导航 跳到搜索 跳到主要内容

PPTSP: patch presence test via semantic normalization and key path extraction

  • Chengke Xu
  • , Senlin Luo
  • , Xueming Duan
  • , Limin Pan*
  • *此作品的通讯作者
  • Beijing Institute of Technology
  • Professor of Information System and Security Countermeasures Experimental Center

科研成果: 期刊稿件文章同行评审

摘要

Determining whether a binary contains a security patch is a critical task in vulnerability analysis. Existing approaches mainly rely on structural similarity of patch features, which limits their ability to identify semantically equivalent but syntactically different binary generated under different compilers and optimization settings. In addition, analyzing binaries at the function level often introduces noise from vendor-added extension code, which increases the false positives. To address these challenges, a semantic-aware patch presence test approach that focus on the control paths affected by the patch is proposed, named Patch presence test via Semantic Normalization and Key Path Extraction (PPTSP). The method first maps semantically equivalent instruction sequences to a unified representation, enhancing feature consistency across different compilation architectures. Then, it identifies the control paths affected by the patch to eliminate interference from irrelevant execution paths during feature extraction. Finally, when features are structurally similar, a large language model (LLM) is leveraged to analyze their semantic equivalence, further enhancing detection accuracy. Experiments demonstrate that PPTSP outperforms current state-of-the-art methods, even under different compiler and optimization level settings.

源语言英语
文章编号26
期刊Software Quality Journal
34
2
DOI
出版状态已出版 - 6月 2026

指纹

探究 'PPTSP: patch presence test via semantic normalization and key path extraction' 的科研主题。它们共同构成独一无二的指纹。

引用此