Sys: A Static/Symbolic Tool for Finding Good Bugs in Good (Browser) Code

Sys: A Static/Symbolic Tool for Finding Good Bugs in Good (Browser) Code
复制标题

DOI:
--
复制
发表时间:
2020
期刊:
--
影响因子:
--
通讯作者:
Fraser Brown;D. Stefan;D. Engler
Fraser Brown;D. Stefan;D. Engler
中科院分区:
其他
文献类型:
--
作者:
Fraser Brown;D. Stefan;D. Engler

文献摘要

被引文献

相似文献

我们描述并评估了一个可扩展的bug查找工具Sys,该工具旨在自动在庞大的代码库中查找安全bug,即使容易找到的bug已经被多年的积极自动检查清除。Sys使用两步方法来发现这种棘手的错误。首先,它使用用户可扩展的静态检查器将数千万行的大型系统分解为小块,以快速查找和标记潜在的错误位置。其次,它使用用户可扩展的符号执行来深入检查这些潜在的错误点,以发现实际的错误。跳棋和系统本身都很小(总共6 Kbps)。Sys是灵活的,因为用户必须能够利用特定于域或系统的知识,以便在真实的代码库中检测错误并抑制误报。Sys在经过严格检查的代码(Chrome和Firefox网络浏览器)和一些符号工具难以处理的代码(FreeBSD操作系统)中发现了许多安全漏洞(51个漏洞,43个已确认)。Sys最有趣的结果包括:Chrome中一个可利用的现金奖励的CVE在7小时内被修复(其补丁在两天内被反向移植); Firefox中一个CVE的三个奖励bug;以及Chrome音频支持中的一个奖励bug。
We describe and evaluate an extensible bug-finding tool, Sys, designed to automatically find security bugs in huge code-bases, even when easy-to-find bugs have been already picked clean by years of aggressive automatic checking. Sys uses a two-step approach to find such tricky errors. First, it breaks down large—tens of millions of lines—systems into small pieces using user-extensible static checkers to quickly find and mark potential errorsites. Second, it uses user-extensible symbolic execution to deeply examine these potential errorsites for actual bugs. Both the checkers and the system itself are small (6KLOC total). Sys is flexible, because users must be able to exploit domain-or system-specific knowledge in order to detect errors and suppress false positives in real codebases. Sys finds many security bugs (51 bugs, 43 confirmed) in well-checked code—the Chrome and Firefox web browsers—and code that some symbolic tools struggle with—the FreeBSD operating system. Sys’s most interesting results include: an exploitable, cash bountied CVE in Chrome that was fixed in seven hours (and whose patch was backported in two days); a trio of bountied bugs with a CVE in Firefox; and a bountied bug in Chrome’s audio support.