Runtime Recovery for Integer Overflows

Runtime Recovery for Integer Overflows
复制标题

DOI:
10.1109/icsrs56243.2022.10067783
复制
发表时间:
2022-11
期刊:
2022 6th International Conference on System Reliability and Safety (ICSRS)
影响因子:
--
通讯作者:
Zhen Huang
Zhen Huang
中科院分区:
其他
文献类型:
--
作者:
Zhen Huang

文献摘要

相似文献

尽管在研究和工程方面进行了数十年的努力,但整数溢出仍然对软件安全仍然是严重的威胁。开发了许多工具来检测运行时整数溢出。但是,当检测到整数溢出时,其中绝大多数终止程序执行。这本质上会导致拒绝服务,这在许多情况下在许多情况下都是不受欢迎的。我们提出了一种旨在从整数溢出中安全恢复的恢复机制。恢复机制检测整数溢出并纠正算术操作中涉及的值,从而导致整数溢出,从而防止整数溢出的发生并使程序能够安全执行。我们设计并开发了一种名为RIO的工具,该工具可以自动合成并启用我们的恢复机制到目标程序中。我们的评估表明,里约热内卢可以成功地合成并仪器将恢复机制纳入包含现实世界脆弱性的程序中,并且仪器恢复机制使程序可以在面对打算触发脆弱性的漏洞的情况下安全地恢复。
Despite decades of effort in research and engineering, integer overflows remain a severe threat to software security. Many tools are developed to detect integer overflows at runtime. However, the vast majority of them terminates program execution when an integer overflow is detected. This essentially causes denial-of-service, which is undesirable in many scenarios in practice. We propose a recovery mechanism designed for safe recovery from integer overflows. The recovery mechanism detects integer overflows and rectifies the values involved in arithmetic operations causing integer overflows so that it prevents the occurrence of the integer overflows and enables the program to continue execute safely. We have designed and developed a tool called RIO that can automatically synthesize and instrument our recovery mechanism into target programs. Our evaluation shows that RIO can successfully synthesize and instrument the recovery mechanism into programs containing real world vulnerabilities and the instrumented recovery mechanism allows the programs to recover safely in the face of exploits intending to trigger the vulnerabilities.