首页> 外文会议>IEEE/ACM International Conference on Automated Software Engineering >Automatically assessing crashes from heap overflows
【24h】

Automatically assessing crashes from heap overflows

机译:自动评估堆溢出导致的崩溃

获取原文

摘要

Heap overflow is one of the most widely exploited vulnerabilities, with a large number of heap overflow instances reported every year. It is important to decide whether a crash caused by heap overflow can be turned into an exploit. Efficient and effective assessment of exploitability of crashes facilitates to identify severe vulnerabilities and thus prioritize resources. In this paper, we propose the first metrics to assess heap overflow crashes based on both the attack aspect and the feasibility aspect. We further present HCSIFTER, a novel solution to automatically assess the exploitability of heap overflow instances under our metrics. Given a heap-based crash, HCSIFTER accurately detects heap overflows through dynamic execution without any source code or debugging information. Then it uses several novel methods to extract program execution information needed to quantify the severity of the heap overflow using our metrics. We have implemented a prototype HCSIFTER and applied it to assess nine programs with heap overflow vulnerabilities. HCSIFTER successfully reports that five heap overflow vulnerabilities are highly exploitable and two overflow vulnerabilities are unlikely exploitable. It also gave quantitatively assessments for other two programs. On average, it only takes about two minutes to assess one heap overflow crash. The evaluation result demonstrates both effectiveness and efficiency of HC Sifter.
机译:堆溢出是最广泛利用的漏洞之一,每年报告大量堆溢出实例。重要的是要决定堆溢出引起的崩溃是否可以变成漏洞。高效有效地对崩溃的利用性评估有助于识别严重漏洞,从而优先考虑资源。在本文中,我们提出了第一项度量来基于攻击方面和可行性方面评估堆溢出崩溃。我们进一步提供了一种新的解决方案,可以自动评估我们指标下堆溢出实例的利用性。鉴于基于堆的崩溃,HCSIFTER通过无任何源代码或调试信息,通过动态执行来精确地检测堆溢出。然后,它使用多种新颖的方法来提取使用我们的指标来量化堆溢出的严重性所需的程序执行信息。我们已经实现了一个原型HCSIFTER,并将其应用于评估剩余溢出漏洞的九个程序。 HCSIFTER成功地报告了五个堆溢出漏洞是高度可利用的,并且两个溢出漏洞不太可能被利用。它还为其他两个方案提供了定量评估。平均而言,评估一个堆溢出崩溃只需要大约两分钟。评估结果表明了HC SiFter的效率和效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号