On the Long-Term Reproducibility of Vulnerable Environments

Entrée en langue anglaise / English entry Catégorie: Conférence avec actes
Auteurs: Olivier Levillain, Nicolas Dejon, Clément Parssegny et Sylvie Laniepce
Date: octobre 2026

Software vulnerabilities fuel ever-growing cyberattacks, even years after their discovery and disclosure to the security community. Their study is thus essential to understand current threats and thwart future flaws; it includes the ability to reproduce attacks and more broadly to access vulnerable environments in the long run. This paper tackles the challenge of long-term reproduction of vulnerable environments.

We present a systematic methodology for creating containerized vulnerable environments using only publicly available data. We evaluate our methodology on a dataset of 142 CVEs, affecting the Debian distribution over a ten-year period, achieving a 41 % reproduction rate. Our analysis reveals key factors that determine reproduction success or failure, and statistical insights about the evolution of the security posture. Moreover, we leverage our 58 successfully reproduced vulnerable environments as a ground truth to check the reliability of two standard vulnerability scanners, which detect 76 % of the CVEs, thereby exposing blind spots for operational security teams. We release our methodology, our corpuses and associated container build descriptions as open-source artifacts to support long-term security research on software vulnerabilities.

Publié dans les actes Information Security Conference (pages 1 à 1)

Présenté lors de la conférence ISC à Rennes, France en octobre 2026

BibTeX