全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

New Binary System for Detecting and Locating Integer-based Vulnerability on Run-time Type Analysis
基于运行时类型分析的整形漏洞二进制检测和定位系统

Keywords: Computer security,Software security,Integer-based vulnerability,Integer overflow
计算安全,软件安全,整形漏洞,整形溢出

Full-Text   Cite this paper   Add to My Lib

Abstract:

Integer-based vulnerability is an extremely serious bug for programs written in languages such as C/C++.Common Vulnerability and Exploit(CVE) shows that as the percentage of buffer overflow has declined,there has been an increase in related vulnerability types,including integer overflows and signedness errors. Here we presented the design, implementation, and evaluation of a tool for run-time detecting and locating integer-based vulnerability. We first translated the binary code into intermediate language VEX on Valgrind, then intercepted integer related statements at run-time, recorded the necessary information, and finally detected and located vulnerability based on the checking scheme. We chose several utility applications, which contain real integer-based vulnerability, to evaluate the effectiveness and run-time performance of our system. Preliminary experimental results are quit promising, it can detect and locate most of integer-based vulnerability in real software, and has very low false positives and negatives.

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133