Testing static analysis tools using exploitable buffer overflows from open source code

Testing static analysis tools using exploitable buffer overflows from open source code
复制标题

DOI:
10.1145/1029894.1029911
复制
发表时间:
2004-10
期刊:
--
影响因子:
--
通讯作者:
Misha Zitser;R. Lippmann;T. Leek
Misha Zitser;R. Lippmann;T. Leek
中科院分区:
其他
文献类型:
--
作者:
Misha Zitser;R. Lippmann;T. Leek

文献摘要

被引文献

相似文献

使用包含Sendmail、BIND和WU-FTPD不同版本中发现的14个可利用的缓冲区溢出漏洞的源代码示例评估了五种现代静态分析工具(ARCHER、布恩、Poly-Space C Verifier、Splint和UNO)。每个代码示例包括一个“BAD”情况和一个“OK”情况。缓冲区溢出各不相同,包括堆栈、堆、缓冲区和数据缓冲区;访问缓冲区边界以上和以下;使用指针、索引和函数进行访问;以及缓冲区创建和使用之间的范围差异。除了Poly-Space和Splint的平均检出率分别为87%和57%之外,“BAD”示例的检出率较低。然而,平均误报率很高,这两种工具的误报率约为50%。在打补丁的程序上,这两个工具每12到46行源代码就会产生一个警告,而且这两个工具似乎都不能准确地区分易受攻击的代码和打补丁的代码。
Five modern static analysis tools (ARCHER, BOON, Poly-Space C Verifier, Splint, and UNO) were evaluated using source code examples containing 14 exploitable buffer overflow vulnerabilities found in various versions of Sendmail, BIND, and WU-FTPD. Each code example included a "BAD" case with and a "OK" case without buffer overflows. Buffer overflows varied and included stack, heap, bss and data buffers; access above and below buffer bounds; access using pointers, indices, and functions; and scope differences between buffer creation and use. Detection rates for the "BAD" examples were low except for Poly-Space and Splint which had average detection rates of 87% and 57%, respectively. However, average false alarm rates were high and roughly 50% for these two tools. On patched programs these two tools produce one warning for every 12 to 46 lines of source code and neither tool appears able to accurately distinguished between vulnerable and patched code.