RICB: Integer Overflow Vulnerability Dynamic Analysis via Buffer Overflow
RICB: Integer Overflow Vulnerability Dynamic Analysis via Buffer Overflow
复制标题
RICB:通过缓冲区溢出进行整数溢出漏洞动态分析
DOI:
10.1007/978-3-642-23602-0_9
复制
发表时间:
2010-11
影响因子:
4.1
通讯作者:
Deng Liwen
中科院分区:
文献类型:
--
作者:
Wang Yong;Gu Dawu;Xu Jianping;Wen Mi;Deng Liwen
Integer overflow vulnerability will cause buffer overflow. The research on the relationship between them will help us to detect integer overflow vulnerability. We present a dynamic analysis methods RICB (Run-time Integer Checking via Buffer overflow). Our approach includes decompile execute file to assembly language; debug the execute file step into and step out; locate the overflow points and checking buffer overflow caused by integer overflow. We have implemented our approach in three buffer overflow types: format string overflow, stack overflow and heap overflow. Experiments results show that our approach is effective and efficient. We have detected more than 5 known integer overflow vulnerabilities via buffer overflow.
登录
查看更多内容
DOI:
10.1002/spe.515
发表时间:
2003-04
期刊:
Software: Practice and Experience
影响因子:
--
作者:
K. Lhee;S. Chapin
通讯作者:
K. Lhee;S. Chapin
DOI:
--
发表时间:
2009
期刊:
--
影响因子:
--
作者:
Tielei Wang;Tao Wei;Zhiqiang Lin;Wei Zou
通讯作者:
Tielei Wang;Tao Wei;Zhiqiang Lin;Wei Zou
DOI:
--
发表时间:
2003
期刊:
--
影响因子:
--
作者:
E. Haugh;M. Bishop
通讯作者:
E. Haugh;M. Bishop
DOI:
--
发表时间:
2008
期刊:
--
影响因子:
--
作者:
Patrice Godefroid;Michael Y. Levin;D. Molnar
通讯作者:
Patrice Godefroid;Michael Y. Levin;D. Molnar
DOI:
10.1016/j.compeleceng.2007.11.002
发表时间:
2008-09
期刊:
Comput. Electr. Eng.
影响因子:
--
作者:
Mustafa Gök
通讯作者:
Mustafa Gök