首页> 外文会议>ACM conference on Computer and communications security >Buffer overrun detection using linear programming and static analysis
【24h】

Buffer overrun detection using linear programming and static analysis

机译:使用线性编程和静态分析的缓冲区溢出检测

获取原文

摘要

This paper addresses the issue of identifying buffer overrun vulnerabilities by statically analyzing C source code. We demonstrate a light-weight analysis based on modeling C string manipulations as a linear program. We also present fast, scalable solvers based on linear programming, and demonstrate techniques to make the program analysis context sensitive. Based on these techniques, we built a prototype and used it to identify several vulnerabilities in popular security critical applications.
机译:本文通过静态分析C源代码来解决识别缓冲区溢出漏洞的问题。我们演示了基于将C字符串操作建模为线性程序的轻量级分析。我们还提出了基于线性编程的快速,可扩展求解器,并演示了使程序分析上下文敏感的技术。基于这些技术,我们构建了一个原型,并将其用于识别流行的关键安全应用程序中的多个漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号