DocumentCode
119390
Title
Understanding Complex Binary Loading Behaviors
Author
Ting Dai ; Mingwei Zhang ; Yap, Roland H. C. ; Zhenkai Liang
Author_Institution
Nat. Univ. of Singapore, Singapore, Singapore
fYear
2014
fDate
4-7 Aug. 2014
Firstpage
49
Lastpage
58
Abstract
Binary loading is used extensively in many operating systems, e.g. Program execution usually involves loading dynamically linked libraries (binaries in DLL form). In Windows, binary loading is used heavily, but the process is complex and is affected by many factors - this flexibility turns out to be a rich source of attacks. When a typical Windows executable runs, many binaries are loaded, possibly from third parties. It is not uncommon for Windows programs to have binary loading vulnerabilities. However, it is difficult for software developers to identify if their programs have such vulnerabilities, how they arise, and how to fix them. We propose LDRSCOPE, to explain why binaries are loaded and detect the factors that affect the loading. This allows developers to better identify the problems and secure their code. We also deal with vulnerabilities arising from software configuration such as configuration files. Some vulnerabilities can also be due to third party libraries, we clearly identify and explain their effects.
Keywords
operating systems (computers); software libraries; user interfaces; DLL; LDRSCOPE; Windows programs; binary loading behaviors; operating systems; program execution; software configuration; source-of-attacks; Libraries; Loading; Operating systems; Payloads; Performance analysis; Rendering (computer graphics);
fLanguage
English
Publisher
ieee
Conference_Titel
Engineering of Complex Computer Systems (ICECCS), 2014 19th International Conference on
Conference_Location
Tianjin
Print_ISBN
978-1-4799-5481-0
Type
conf
DOI
10.1109/ICECCS.2014.15
Filename
6923117
Link To Document