Non-Distinguishable Inconsistencies as a Deterministic Oracle for Detecting Security Bugs

Non-Distinguishable Inconsistencies as a Deterministic Oracle for Detecting Security Bugs
复制标题

DOI:
10.1145/3548606.3560661
复制
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Qingyang Zhou;Qiushi Wu;Dinghao Liu;S. Ji;Kangjie Lu
Qingyang Zhou;Qiushi Wu;Dinghao Liu;S. Ji;Kangjie Lu
中科院分区:
其他
文献类型:
--
作者:
Qingyang Zhou;Qiushi Wu;Dinghao Liu;S. Ji;Kangjie Lu

文献摘要

相似文献

像内存错误这样的安全错误不断地被引入软件程序中,近年来报告的安全错误的数量越来越多。传统的检测方法主要是基于规范的-将违反指定规则的行为检测为安全错误。这在实践中通常不能很好地工作,因为规范很难指定和泛化,留下了复杂和新类型的错误没有被发现。因此,最近的研究倾向于基于偏差的检测,它发现了大量类似的案例,并将偏差案例检测为潜在的错误。然而,这还存在另外两个问题。首先,它需要足够多的相似用例来查找偏差,因此不能用于没有相似用例的定制代码。其次,代码相似性分析是概率和挑战性的,因此检测可能不可靠。有时,类似的案例在不同的情况下通常会有偏离行为。基于不可区分不一致(NDI)的概念,提出了一种新的安全漏洞检测方法。其中的见解是,如果函数中的两个代码路径表现出与外部(如调用方)无法区分的不一致的安全状态(如被释放或初始化),则无法从外部的不一致中恢复,这将导致错误。这种方法有几个优点。首先,它是无规范的,因此可以支持复杂和新类型的错误。其次,它不需要类似的案例,从本质上讲是确定性的。第三,通过最大限度地减少复杂和冗长的数据流分析,该分析具有实用性。我们实现了NDI,并将其应用于经过良好测试的程序,包括OpenSSL库、FreeBSD内核、ApacheHTTPD服务器和PHP解释器。结果表明,NDI既适用于大程序,也适用于小程序,它有效地发现了51个新错误,其中大多数都被最先进的检测工具遗漏了。
Security bugs like memory errors are constantly introduced to software programs, and recent years have witnessed an increasing number of reported security bugs. Traditional detection approaches are mainly specification-based---detecting violations against a specified rule as security bugs. This often does not work well in practice because specifications are difficult to specify and generalize, leaving complicated and new types of bugs undetected. Recent research thus leans toward deviation-based detection which finds a substantial number of similar cases and detects deviating cases as potential bugs. This, however, suffers from two other problems. First, it requires enough similar cases to find deviations and thus cannot work for custom code that does not have similar cases. Second, code-similarity analysis is probabilistic and challenging, so the detection can be unreliable. Sometimes, similar cases can normally have deviating behaviors under different contexts. In this paper, we propose a novel approach for detecting security bugs based on a new concept called Non-Distinguishable Inconsistencies (NDI). The insight is that if two code paths in a function exhibit inconsistent security states (such as being freed or initialized) that are non-distinguishable from the external, such as the callers, there is no way to recover from the inconsistency from the external, which results in a bug. Such an approach has several strengths. First, it is specification-free and thus can support complicated and new types of bugs. Second, it does not require similar cases and by its nature is deterministic. Third, the analysis is practical by minimizing complicated and lengthy data-flow analysis. We implemented NDI and applied it to well-tested programs, including the OpenSSL library, the FreeBSD kernel, the Apache httpd server, and the PHP interpreter. The results show that NDI works for both large and small programs, and it effectively found 51 new bugs, most of which are otherwise missed by the state-of-the-art detection tools.