VCPEC: Vulnerability Correlation Analysis Based on Privilege Escalation and Coritivity Theory.

Xuefei Wang,Rui Ma,Donghai Tian,Xiajing Wang
DOI: https://doi.org/10.1145/3442520.3442526
2020-01-01
Abstract:Vulnerability correlation analysis has become a key technique in the field of vulnerability analysis, which effectively addresses the limitation of only analyzing an isolated vulnerability. Even though the existing techniques have demonstrated their effectiveness in assessing the complex relationship between the vulnerabilities, they remain limited in accurately locating critical vulnerabilities. To overcome this issue, we design a vulnerability correlation analysis method, named VCPEC, to discover critical vulnerabilities using extended coritivity theory towards a novel privilege model. The key idea is to construct a vulnerability correlation graph (VCG) according to the system privilege grading strategy and the vulnerability privilege escalation paths, reducing the complexity in the graph. Then use the extended coritivity theory to calculate the core of the VCG, that means the critical vulnerabilities can be further recognized. Thus, by repairing critical vulnerabilities to achieve efficient protection of target system, saving the cost of repairing vulnerabilities. We design and perform experiments to verify the feasibility and efficiency of VCPEC in real-world software systems. And the results show that VCPEC can accurately locate critical vulnerabilities.
What problem does this paper attempt to address?