Towards Practical Reactive Security Audit Using Extended Static Checkers

Towards Practical Reactive Security Audit Using Extended Static Checkers
复制标题

DOI:
10.1109/sp.2013.12
复制
发表时间:
2013-05
期刊:
2013 IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Julien Vanegue;Shuvendu K. Lahiri
Julien Vanegue;Shuvendu K. Lahiri
中科院分区:
其他
文献类型:
--
作者:
Julien Vanegue;Shuvendu K. Lahiri

文献摘要

被引文献

相似文献

本文介绍了我们的经验,在核心操作系统和浏览器COM组件的已知安全漏洞进行反应式安全审计,使用扩展的静态检查HAVOCLITE。我们描述的扩展工具,适用于这样的大型C++组件,沿着我们的经验,使用一个扩展的静态检查器在大。我们认为,使用这种检查器作为一个可配置的静态分析手中的安全审计人员可以找到已知的漏洞的变化是一个有效的工具。这项工作已经在超过1000万行的操作系统和浏览器代码中发现并修复了大约70个以前未知的安全漏洞。
This paper describes our experience of performing reactive security audit of known security vulnerabilities in core operating system and browser COM components, using an extended static checker HAVOCLITE. We describe the extensions made to the tool to be applicable on such large C++ components, along with our experience of using an extended static checker in the large. We argue that the use of such checkers as a configurable static analysis in the hands of security auditors can be an effective tool for finding variations of known vulnerabilities. The effort has led to finding and fixing around 70 previously unknown security vulnerabilities in over 10 millions lines operating system and browser code.