• DocumentCode
    2845342
  • Title

    Finding Buffer Overflow Inducing Loops in Binary Executables

  • Author

    Rawat, Sanjay ; Mounier, Laurent

  • Author_Institution
    Verimag Lab., Univ. of Grenoble, Grenoble, France
  • fYear
    2012
  • fDate
    20-22 June 2012
  • Firstpage
    177
  • Lastpage
    186
  • Abstract
    Vulnerability analysis is one among the important components of overall software assurance practice. Buffer overflow (BoF) is one example of the such vulnerabilities and it is still the root cause of many effective attacks. A general practice to find BoF is to look for the presence of certain functions that manipulate string buffers, like the strcpy family. In these functions, data is moved from one buffer to another, within a loop, without considering destination buffer size. We argue that similar behaviour may also be present in many other functions that are coded separately, and therefore are equally vulnerable. In the present work, we investigate the detection of such functions by finding loops that exhibit similar behaviour. We call such loops Buffer Overflow Inducing Loops (BOIL). We implemented a lightweight static analysis to detect BOILs, and evaluated it on real-world x86 binary executables. The results obtained show that this (simple but yet efficient) vulnerability pattern happens to be very effective in practice to retrieve real vulnerabilities, providing a drastic reduction of the part of the code to be analysed.
  • Keywords
    buffer storage; program diagnostics; security of data; software reliability; BOIL; BoF; buffer overflow inducing loops; certain functions; code analysis; destination buffer size; drastic reduction; lightweight static analysis; real vulnerability; real-world x86 binary executables; software assurance practice; strcpy family; string buffers; vulnerability analysis; vulnerability pattern; Arrays; Assembly; Binary codes; Libraries; Registers; Security; Software; Buffer overflow; binary code; dependency chain; loop detection; security vulnerability; static analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference on
  • Conference_Location
    Gaithersburg, MD
  • Print_ISBN
    978-1-4673-2067-2
  • Type

    conf

  • DOI
    10.1109/SERE.2012.30
  • Filename
    6258307