Testing C Programs for Buffer Overflow Vulnerabilities
Testing C Programs for Buffer Overflow Vulnerabilities
复制标题
DOI:
--
复制
发表时间:
2003
期刊:
影响因子:
--
通讯作者:
E. Haugh;M. Bishop
中科院分区:
文献类型:
--
作者:
E. Haugh;M. Bishop
Security vulnerabilities often result from buffer overflows. A testing technique that instruments programs with code that keeps track of memory buffers, and checks arguments to functions to determine if they satisfy certain conditions, warns when a buffer overflow may occur. It does so when executed with ”normal” test data as opposed to test data designed to trigger buffer overflows. A tool using this method was developed and evaluated by testing three widely used, open source software packages. This evaluation shows that the tool is useful for finding buffer overflow flaws, that it has a low false positive rate, and compares well with other techniques.