RICB: Integer Overflow Vulnerability Dynamic Analysis via Buffer Overflow

RICB: Integer Overflow Vulnerability Dynamic Analysis via Buffer Overflow
复制标题

RICB:通过缓冲区溢出进行整数溢出漏洞动态分析

DOI:
10.1007/978-3-642-23602-0_9
复制
发表时间:
2010-11
影响因子:
4.1
通讯作者:
Deng Liwen
Deng Liwen
中科院分区:
计算机科学3区
文献类型:
--
作者:
Wang Yong;Gu Dawu;Xu Jianping;Wen Mi;Deng Liwen

文献摘要

参考文献

被引文献

相似文献

整数溢出漏洞会导致缓冲区溢出。研究它们之间的关系有助于我们检测整数溢出漏洞。提出了一种动态分析方法RICB(通过缓冲区溢出进行运行时整数检查)。我们的方法包括将执行文件反编译为汇编语言;调试执行文件的步进和步出;定位溢出点,检查由整数溢出引起的缓冲区溢出。我们已经在三种缓冲区溢出类型中实现了我们的方法:格式字符串溢出、堆栈溢出和堆溢出。实验结果表明,该方法是有效的。我们已经通过缓冲区溢出检测到超过5个已知的整数溢出漏洞。
Integer overflow vulnerability will cause buffer overflow. The research on the relationship between them will help us to detect integer overflow vulnerability. We present a dynamic analysis methods RICB (Run-time Integer Checking via Buffer overflow). Our approach includes decompile execute file to assembly language; debug the execute file step into and step out; locate the overflow points and checking buffer overflow caused by integer overflow. We have implemented our approach in three buffer overflow types: format string overflow, stack overflow and heap overflow. Experiments results show that our approach is effective and efficient. We have detected more than 5 known integer overflow vulnerabilities via buffer overflow.
DOI: 10.1002/spe.515
发表时间: 2003-04
期刊: Software: Practice and Experience
影响因子: --
作者:
K. Lhee;S. Chapin
通讯作者: K. Lhee;S. Chapin
DOI: --
发表时间: 2009
期刊: --
影响因子: --
作者:
Tielei Wang;Tao Wei;Zhiqiang Lin;Wei Zou
通讯作者: Tielei Wang;Tao Wei;Zhiqiang Lin;Wei Zou
DOI: --
发表时间: 2003
期刊: --
影响因子: --
作者:
E. Haugh;M. Bishop
通讯作者: E. Haugh;M. Bishop
DOI: --
发表时间: 2008
期刊: --
影响因子: --
作者:
Patrice Godefroid;Michael Y. Levin;D. Molnar
通讯作者: Patrice Godefroid;Michael Y. Levin;D. Molnar
DOI: 10.1016/j.compeleceng.2007.11.002
发表时间: 2008-09
期刊: Comput. Electr. Eng.
影响因子: --
作者:
Mustafa Gök
通讯作者: Mustafa Gök