IntScope: Automatically Detecting Integer Overflow Vulnerability in X86 Binary Using Symbolic Execution

IntScope: Automatically Detecting Integer Overflow Vulnerability in X86 Binary Using Symbolic Execution
复制标题

DOI:
--
复制
发表时间:
2009
期刊:
--
影响因子:
--
通讯作者:
Tielei Wang;Tao Wei;Zhiqiang Lin;Wei Zou
Tielei Wang;Tao Wei;Zhiqiang Lin;Wei Zou
中科院分区:
其他
文献类型:
--
作者:
Tielei Wang;Tao Wei;Zhiqiang Lin;Wei Zou

文献摘要

被引文献

相似文献

近年来,已识别的整数溢出漏洞的数量迅速增加。在本文中,我们提出了一个系统,IntScope,它可以自动检测整数溢出漏洞的x86二进制文件的攻击者之前,最终消除漏洞的目标。IntScope首先将反汇编的代码转换为我们自己的中间表示(IR),然后通过利用符号执行和污点分析来识别整数溢出的脆弱点,对IR执行路径敏感的数据流分析。与其他方法相比,IntScope不直接运行二进制文件,并且可以扩展到大型软件,因为它可以象征性地执行感兴趣的程序路径。实验结果表明IntScope非常令人鼓舞:它已经检测到超过20个零日整数溢出(例如,CVE-2008-4201,FrSIRT/ADV-2008-2919)在广泛使用的软件中,如QEMU、Xen和Xine。
The number of identified integer overflow vulnerabilities has been increasing rapidly in recent years. In this paper, we present a system, IntScope, which can automatically detect integer overflow vulnerabilities in x86 binaries before an attacker does, with the goal of finally eliminating the vulnerabilities. IntScope first translates the disassembled code into our own intermediate representation (IR), and then performs a path sensitive data flow analysis on the IR by leveraging symbolic execution and taint analysis to identify the vulnerable point of integer overflow. Compared with other approaches, IntScope does not run the binary directly, and is scalable to large software as it can just symbolically execute the interesting program paths. Experimental results show IntScope is quite encouraging: it has detected more than 20 zero-day integer overflows (e.g., CVE-2008-4201, FrSIRT/ADV-2008-2919) in widely-used software such as QEMU, Xen and Xine.