Towards Tackling Application Logic Flaws through Autonomous Formal-Logic Modeling and Automated Reasoning

📅 2026-09-09
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出LL-Verifier框架,利用大型语言模型自动生成形式逻辑模型,并通过逻辑模型检查器进行严格推理,以解决应用程序中的逻辑缺陷问题。
📝 Abstract
Logic flaws pose significant challenges in the design and implementation of modern, semantically rich systems and applications, impacting security, privacy, and trust. These flaws are inherently tied to business-specific semantics and threat models, making their discovery and reasoning difficult and hard to scale. Real-world systems often exhibit diverse application features, complex protocol logic, and domain-specific threat models, necessitating substantial human effort and domain expertise for effective security analysis. In this paper, we introduce LL-Verifier, a novel, automated framework for identifying logic vulnerabilities built on (1) large language models for autonomous modeling, and (2) logic model checkers for rigorous reasoning. LL-Verifier processes natural language inputs, in particular protocol descriptions and security goals, to automatically generate formal logic models and properties expressed in a new logic language built on a generic logic language Maude, optimized for modeling arbitrary application-level semantics. These formal models are then converted into logical state machines, enabling exhaustive, rigorous verification through logic level model checking. This approach streamlines the analysis of diverse, application-level protocols deployed in real-world scenarios, offering automated, exhaustive, and precise reasoning within their logical constraints. We evaluated the high effectiveness, efficiency, and practicality of LL-Verifier by applying it to 27 access control protocols of widely used IoT devices, which come with vendor-specific logic flows and semantics. While LL-verifier tackles a hard problem in application security, i.e., automatic logic flaws discovery, our analysis uncovers a range of sophisticated logic vulnerabilities in IoT protocols and devices with serious security and privacy implications.
Problem

Research questions and friction points this paper is trying to address.

Logic Flaws
Security Analysis
Application Logic
Automated Reasoning
Formal-Logic Modeling
Innovation

Methods, ideas, or system contributions that make the work stand out.

large language models
logic model checkers
automated reasoning
formal logic models
logical state machines
Y
Yiwei Fang
Institute of Information Engineering, Chinese Academy of Sciences
Y
Yichen Liu
University of Illinois Urbana-Champaign
Z
Ze Jin
Institute of Information Engineering, Chinese Academy of Sciences
H
Haoqiang Wang
Institute of Information Engineering, Chinese Academy of Sciences
Q
Qixu Liu
Institute of Information Engineering, Chinese Academy of Sciences
Luyi Xing
Luyi Xing
Associate Professor of Computer Science, University of Illinois Urbana-Champaign/Indiana University
System SecurityData Privacy and Cybercrime