首页> 外文会议>International symposium on research in attacks, intrusions and defenses >Improving Accuracy of Static Integer Overflow Detection in Binary
【24h】

Improving Accuracy of Static Integer Overflow Detection in Binary

机译:提高二进制静态整数溢出检测的准确性

获取原文

摘要

Integer overflow presents a major source of security threats to information systems. However, current solutions are less effective in detecting integer overflow vulnerabilities: they either produce unaccept-ably high false positive rates or cannot generate concrete inputs towards vulnerability exploration. This limits the usability of these solutions in analyzing real-world applications, especially those in the format of binary executables. In this paper, we present a platform, called INDIO, for accurately detecting integer overflow vulnerabilities in Windows binaries. INDIO integrates the techniques of pattern-matching (for quick identification of potential vulnerabilities), vulnerability ranking (for economic elimination of false positives), and selective symbolic execution (for rigorous elimination of false positives). As a result, INDIO can detect integer overflow with low false positive and false negative rates. We have applied INDIO to several real-world, large-size Windows binaries, and the experimental results confirmed the effectiveness of INDIO (all known and two previously unknown integer overflows vulnerabilities were detected). The experiments also demonstrate that the vulnerability ranking technique and other optimization techniques employed in INDIO can significantly reduce false positives with economic costs.
机译:整数溢出是信息系统安全威胁的主要来源。但是,当前的解决方案在检测整数溢出漏洞方面效率较低:它们要么产生令人无法接受的高误报率,要么无法为漏洞探索提供具体的输入。这限制了这些解决方案在分析实际应用程序(尤其是二进制可执行文件格式的应用程序)中的可用性。在本文中,我们提出了一个名为INDIO的平台,用于准确检测Windows二进制文件中的整数溢出漏洞。 INDIO集成了模式匹配(用于快速识别潜在漏洞),漏洞排名(用于经济消除误报)和选择性符号执行(用于严格消除误报)技术。结果,INDIO可以以低的误报率和误报率检测整数溢出。我们已将INDIO应用于多个实际的大型Windows二进制文件,并且实验结果证实了INDIO的有效性(已检测到所有已知和两个以前未知的整数溢出漏洞)。实验还证明,INDIO中使用的漏洞排名技术和其他优化技术可以显着减少误报,并降低经济成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号