Testing C Programs for Buffer Overflow Vulnerabilities

Testing C Programs for Buffer Overflow Vulnerabilities
复制标题

DOI:
--
复制
发表时间:
2003
期刊:
--
影响因子:
--
通讯作者:
E. Haugh;M. Bishop
E. Haugh;M. Bishop
中科院分区:
其他
文献类型:
--
作者:
E. Haugh;M. Bishop

文献摘要

被引文献

相似文献

安全漏洞通常由缓冲区溢出引起。一种测试技术,它使用跟踪内存缓冲区的代码来检测程序,并检查函数的参数以确定它们是否满足某些条件,并在可能发生缓冲区溢出时发出警告。当使用“正常”测试数据执行时,而不是使用设计用于触发缓冲区溢出的测试数据执行时,它会这样做。使用这种方法开发的工具,并通过测试三个广泛使用的开放源码软件包进行评估。该评估表明,该工具对于发现缓冲区溢出缺陷是有用的,它具有较低的误报率,并且与其他技术相比也很好。
Security vulnerabilities often result from buffer overflows. A testing technique that instruments programs with code that keeps track of memory buffers, and checks arguments to functions to determine if they satisfy certain conditions, warns when a buffer overflow may occur. It does so when executed with ”normal” test data as opposed to test data designed to trigger buffer overflows. A tool using this method was developed and evaluated by testing three widely used, open source software packages. This evaluation shows that the tool is useful for finding buffer overflow flaws, that it has a low false positive rate, and compares well with other techniques.