LoongChecker: Practical Summary-Based Semi-simulation to Detect Vulnerability in Binary Code

Autor: Jiajie Wang, Fan Jiang, Shaoyin Cheng, Jinding Wang, Jun Yang
Rok vydání: 2011
Předmět:
Zdroj: TrustCom
DOI: 10.1109/trustcom.2011.22
Popis: The automatic detection of security vulnerabilities in binary code is challenging and lacks efficient tools. This paper presents a novel semi-simulation approach to statically detect potential vulnerabilities in binary code. The semi-simulation approach simulates address related instructions accurately using value set analysis, and only traces data dependence on other instructions using data dependence analysis. We have implemented this approach on a tool called LoongChecker, and evaluate it on three real world programs, and detect three known vulnerabilities and two zero-day vulnerabilities. The results show our approach is practical and can be applied to large real world software.
Databáze: OpenAIRE