分析14年公开安全公告,发现Qubes系统漏洞主要来自上游组件。
Qubes OS Security in the Public Record

- 通过追踪109份安全公告和464个XSA,精准定位漏洞来源。
- 79.8%的漏洞归因于Xen、CPU等上游组件,非Qubes核心代码。
- 漏洞披露量2015年后趋于平稳,但长期集中于关键上游依赖项。
Qubes OS 是安全度量研究的典型案例,因其架构使组件边界具有安全意义。本文对2011至2025年间发布的109份官方Qubes安全公告(QSBs)、Qubes维护的Xen安全通告(XSA)追踪记录,以及次级漏洞事件敏感性系列进行了协议驱动的纵向分析。研究聚焦于公开通告记录,而非潜在漏洞数量或实际攻击。方法包括经审计的确定性组件归因、变点分析、过度分散检验、严重性代理加权、删失敏感性分析、文档延迟下限估计,以及基线感知的漏洞发现模型(VDM)评估。结果显示,公开记录中存在持续的上游依赖。在官方追踪中,464个XSA中有113个影响Qubes;按主标签划分,109份QSB中87份(79.8%)可归因于Xen、CPU/微架构或其他上游组件,加权视角下结果一致。变点分析识别出2015年第一季度为季度公告序列的主要断裂点,而2018年后年度披露率统计上保持平稳。泊松推断在分散诊断与负二项敏感性检查下仍稳定。分层30份公告的归因编码本表现良好;S型VDM虽描述性拟合良好,但在短期预测中未显著优于滚动均值基线。总体而言,Qubes的公开安全记录呈稳定状态,但并非平静:披露活动在较高水平趋于平缓,且风险仍高度集中于上游信任锚点。
原文摘要 · Abstract (English)
Qubes OS is a revealing case for security measurement because its architecture makes component boundaries security-relevant. We present a protocol-driven longitudinal analysis of 109 public Qubes Security Bulletins (QSBs, 2011--2025), the official Qubes-maintained Xen Security Advisory (XSA) tracker, and a secondary vulnerability-event sensitivity series. The study measures the public advisory record rather than latent vulnerability incidence or realized compromise. The methodology combines audited deterministic component attribution, change-point analysis, overdispersion checks, severity-proxy weighting, censoring sensitivity, documentary latency lower bounds, and baseline-aware evaluation of vulnerability discovery models (VDMs). The results show persistent upstream dependence in that public record. On the official tracker, 113 of 464 XSAs affect Qubes; under primary labeling, 87 of 109 QSBs (79.8\%) are attributable to Xen, CPU/microarchitectural, or other upstream components rather than Qubes-core logic, with similar results under weighted views. Change-point analyses identify 2015Q1 as the dominant break in the quarterly advisory series, while post-2018 annual disclosure rates are statistically flat. Poisson inferences are stable under dispersion diagnostics and negative-binomial sensitivity checks. The attribution codebook performs well in a stratified 30-QSB audit, and S-shaped VDMs fit descriptively but do not significantly outperform a rolling-mean baseline in short-horizon forecasts. Overall, the Qubes public advisory record appears stable, but not quiet: disclosure activity plateaus at a higher level than in the earliest years, while the observed burden remains concentrated in upstream trust anchors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。