سلامة الذاكرة في تطوير النواة: دراسة مقارنة بمساعدة الذكاء الاصطناعي بين نهجي Rust و C في منع تلف الذاكرة
DOI:
https://doi.org/10.65405/zhcpaq10الكلمات المفتاحية:
سلامة الذاكرة، لغة Rust، لغة C، تطوير النواة، تلف الذاكرة، اكتشاف الثغرات، الذكاء الاصطناعيالملخص
تُعدّ مشكلات تلف الذاكرة من أهم مصادر الثغرات الأمنية في البرمجيات منخفضة المستوى والبرمجيات المرتبطة بتطوير نواة نظام التشغيل، وخصوصًا في الأنظمة المطوّرة بلغة C، حيث يؤدي الاعتماد على إدارة الذاكرة يدويًا إلى ظهور أخطاء مثل تجاوز حدود الذاكرة، واستخدام الذاكرة بعد تحريرها، والتحرير المزدوج للذاكرة، والوصول إلى مؤشر فارغ، وتسرب الذاكرة. تقدم هذه الورقة إطارًا مقارنًا بمساعدة الذكاء الاصطناعي يسمى KernelMemSafe-AI لتقييم سلوك سلامة الذاكرة في النهجين المعتمدين على لغتي C وRust ضمن سياق تطوير النواة. يجمع الإطار المقترح بين مكوّنين متكاملين: مصنّف ذكي لاكتشاف أنماط الثغرات، وتجارب عملية تقارن بين تطبيقات C وRust. تم إنشاء مجموعة بيانات متوازنة ومضبوطة تتكون من 520 مقطعًا برمجيًا بلغة C/C++ وبأسلوب قريب من برمجة النواة، وتم تصنيفها إلى مقاطع آمنة ومقاطع معرضة للثغرات عبر عدة فئات من أخطاء تلف الذاكرة. اعتمد المصنّف الهجين على تحليل الرموز والثنائيات النصية، وخوارزمية Naive Bayes، ومؤشرات قائمة على قواعد سلامة الذاكرة، ودرجات الثقة، والتحقق المتقاطع بخمسة أجزاء. حقق المصنّف دقة بلغت 95.58%، ودقة إيجابية 96.11%، واسترجاعًا 95.00%، وقيمة F1 بلغت 95.55%. كما تم تنفيذ خمس تجارب عملية لقياس سلوك اللغتين في حالات تجاوز حدود الذاكرة، واستخدام الذاكرة بعد تحريرها، والتحرير المزدوج، والوصول إلى مؤشر فارغ، وتسرب الذاكرة. أظهرت النتائج أن كود C غالبًا ما يُترجم بنجاح رغم أنه قد يؤدي أثناء التشغيل إلى فشل وقت التنفيذ أو سلوك غير معرّف أو انهيار في مخصّص الذاكرة أو قيم غير صحيحة أو ذاكرة غير محررة. في المقابل، تمنع Rust أو تقلل العديد من هذه الأخطاء من خلال الملكية، ونقل الملكية، وفحص حدود المصفوفات، واستخدام Option<T>، والتنظيف التلقائي عبر Drop. وتبيّن النتائج أن Rust توفر حماية أقوى على مستوى اللغة ضد أنماط تلف الذاكرة الشائعة، بينما يساعد التحليل المدعوم بالذكاء الاصطناعي في الاكتشاف المبكر لأنماط كود C غير الآمنة. وبشكل عام، توضح الدراسة أن الجمع بين آليات البرمجة الآمنة للذاكرة والتحليل الذكي للثغرات يمكن أن يعزز موثوقية وأمن البرمجيات الموجهة لتطوير النواة.
التنزيلات
المراجع
[1] National Security Agency, “Software Memory Safety,” Cybersecurity Information Sheet, Nov. 2022.
[2] Microsoft Security Response Center, “We Need a Safer Systems Programming Language,” Microsoft Security Blog, Jul. 2019.
[3] H. Li, L. Guo, Y. Yang, S. Wang, and M. Xu, “An Empirical Study of Rust-for-Linux: The Success, Dissatisfaction, and Compromise,” in Proc. 2024 USENIX Annual Technical Conference (USENIX ATC), Santa Clara, CA, USA, 2024.
[4] Z. Li, A. Narayanan, M. M. Swift, and S. Jha, “Understanding the Security Impact of Rust in the Linux Kernel,” in Proc. Annual Computer Security Applications Conference (ACSAC), 2024.
[5] S. K. Panter and N. U. Eisty, “Rusty Linux: Advances in Rust for Linux Kernel Development,” in Proc. 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), 2024, pp. 496–502.
[6] H. Li, L. Guo, Y. Yang, S. Wang, and M. Xu, “Rust Meets Linux: Lessons from an Evolving Experiment,” ACM Transactions on Computer Systems, 2026.
[7] F. Garber, “Rust in the Linux Kernel: Analyzing Rust Implementations of Virtual General Purpose Input Output Drivers,” M.S. thesis, Technische Universität Wien, Vienna, Austria, 2025.
[8] A. Syalim and D. P. Sheradhien, “C vs Rust: Manual vs Automatic Spatial and Temporal Memory Safety,” The Indonesian Journal of Computer Science, vol. 14, no. 2, pp. 2197–2213, 2025.
[9] J. Fan, Y. Li, S. Wang, and T. N. Nguyen, “A C/C++ Code Vulnerability Dataset with Code Changes and CVE Summaries,” in Proc. 17th International Conference on Mining Software Repositories (MSR), Seoul, South Korea, 2020, pp. 508–512.
[10] S. Chakraborty, R. Krishna, Y. Ding, and B. Ray, “Deep Learning Based Vulnerability Detection: Are We There Yet?,” IEEE Transactions on Software Engineering, vol. 48, no. 9, pp. 3280–3296, 2022.
[11] M. Fu and C. Tantithamthavorn, “LineVul: A Transformer-Based Line-Level Vulnerability Prediction,” in Proc. 19th International Conference on Mining Software Repositories (MSR), Pittsburgh, PA, USA, 2022, pp. 608–620.
[12] Y. Chen, Z. Ding, L. Alowain, X. Chen, and D. Wagner, “DiverseVul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability Detection,” in Proc. 26th International Symposium on Research in Attacks, Intrusions and Defenses (RAID), Hong Kong, China, 2023, pp. 654–668.
[13] H. Hanif and S. Maffeis, “VulBERTa: Simplified Source Code Pre-Training for Vulnerability Detection,” in Proc. International Joint Conference on Neural Networks (IJCNN), 2022.
[14] Y. Li, S. Wang, and T. N. Nguyen, “Vulnerability Detection with Fine-Grained Interpretations,” in Proc. 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE), 2021.
[15] S. Cao, X. Sun, L. Bo, Y. Wei, and B. Li, “BGNN4VD: Constructing Bidirectional Graph Neural-Network for Vulnerability Detection,” Information and Software Technology, vol. 136, 2021.
[16] G. Lin, J. Zhang, W. Luo, L. Pan, O. De Vel, P. Montague, and Y. Xiang, “Software Vulnerability Discovery via Learning Multi-Domain Knowledge Bases,” IEEE Transactions on Dependable and Secure Computing, vol. 18, no. 5, pp. 2469–2485, 2021.
[17] C. Liang, L. Wang, Y. Zhang, and Z. Jin, “Survey of Source Code Vulnerability Analysis Based on Deep Learning,” Computers & Security, vol. 146, 2025.
[18] H. Su, X. Li, Y. Zhang, and J. Wang, “Source Code Vulnerability Detection Based on Deep Learning: A Review,” Discover Computing, 2026.
[19] X. He, Y. Wang, and L. Zhang, “An Improved Software Source Code Vulnerability Detection Model Based on Multi-Feature Screening and Integrated Sampling,” Sensors, vol. 25, no. 6, 2025.
[20] Z. Sheng, K. Tian, and D. Lo, “LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights,” ACM Computing Surveys, 2025.











