首页> 外文会议>International conference on swarm intelligence >HYBit: A Hybrid Taint Analyzing Framework for Binary Programs
【24h】

HYBit: A Hybrid Taint Analyzing Framework for Binary Programs

机译:HYBit:二进制程序的混合污染分析框架

获取原文

摘要

For the purpose of discovering security flaws in software, many dynamic and static taint analyzing techniques have been proposed. The dynamic techniques can precisely find the security flaws of the software; but it suffers from substantial runtime overhead. On the other hand, the static techniques require no runtime overhead; but it is often not accurate enough. In this paper, we propose HYBit, a novel hybrid framework which integrates dynamic and static taint analysis to diagnose the security flaws for binary programs. In the framework, the source binary is first analyzed by the dynamic taint analyzer; then, with the runtime information provided by its dynamic counterpart, the static taint analyzer can process the unexecuted part of the target program easily. Furthermore, a taint behavior filtration mechanism is proposed to optimize the performance of the framework. We evaluate our framework from three perspectives: efficiency, coverage, and effectiveness, and the results are encouraging.
机译:为了发现软件中的安全漏洞,已经提出了许多动态和静态的污点分析技术。动态技术可以精确地发现软件的安全漏洞;但它会遭受大量的运行时开销。另一方面,静态技术不需要运行时开销。但是通常不够准确。在本文中,我们提出了HYBit,这是一种新颖的混合框架,该框架结合了动态和静态污点分析功能,可以诊断二进制程序的安全漏洞。在该框架中,首先通过动态污点分析器分析源二进制文件。然后,利用其动态副本提供的运行时信息,静态污点分析器可以轻松地处理目标程序的未执行部分。此外,提出了一种污点行为过滤机制,以优化框架的性能。我们从三个角度评估我们的框架:效率,覆盖范围和有效性,其结果令人鼓舞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号