BovInspector: automatic inspection and repair of buffer overflow vulnerabilities

作者: Fengjuan Gao , Linzhang Wang , Xuandong Li

DOI: 10.1145/2970276.2970282

关键词: Source codeStatic analysisBuffer overflowSoftwareComputer scienceReal-time computingSymbolic executionFalse positive paradox

摘要: … t buffer overflow vulnerability warnings output by existing static program analysis tools for C programs, as well as repair validated true buffer overflow vulnerabilities… static buffer overflow …

参考文章(11)
Tzi-cker Chiueh, Alexey Smirnov, DIRA: Automatic Detection, Identification and Repair of Control-Hijacking Attacks. network and distributed system security symposium. ,(2005)
Stelios Sidiroglou-Douskos, Martin Rinard, Eric Lahtinen, Automatic Discovery and Patching of Buffer and Integer Overflow Errors ,(2015)
Eric A. Brewer, Alexander Aiken, David A. Wagner, Jeffrey S. Foster, A First Step Towards Automated Detection of Buffer Overrun Vulnerabilities. network and distributed system security symposium. ,(2000)
Matt Bishop, Eric Haugh, Testing C Programs for Buffer Overflow Vulnerabilities. network and distributed system security symposium. ,(2003)
Wei Le, Mary Lou Soffa, Marple Proceedings of the 16th ACM SIGSOFT International Symposium on Foundations of software engineering - SIGSOFT '08/FSE-16. pp. 272- 282 ,(2008) , 10.1145/1453101.1453137
Stelios Sidiroglou-Douskos, Eric Lahtinen, Fan Long, Martin Rinard, Automatic error elimination by horizontal code transfer across multiple applications programming language design and implementation. ,vol. 50, pp. 43- 54 ,(2015) , 10.1145/2737924.2737988
Jeff H. Perkins, Greg Sullivan, Weng-Fai Wong, Yoav Zibin, Michael D. Ernst, Martin Rinard, Sunghun Kim, Sam Larsen, Saman Amarasinghe, Jonathan Bachrach, Michael Carbin, Carlos Pacheco, Frank Sherwood, Stelios Sidiroglou, Automatically patching errors in deployed software symposium on operating systems principles. pp. 87- 102 ,(2009) , 10.1145/1629575.1629585
D. Evans, D. Larochelle, Improving security using extensible lightweight static analysis IEEE Software. ,vol. 19, pp. 42- 51 ,(2002) , 10.1109/52.976940
Ru-Gang Xu, Patrice Godefroid, Rupak Majumdar, Testing for buffer overflows with length abstraction Proceedings of the 2008 international symposium on Software testing and analysis - ISSTA '08. pp. 27- 38 ,(2008) , 10.1145/1390630.1390636
Hossain Shahriar, Mohammad Zulkernine, Mutation-Based Testing of Buffer Overflow Vulnerabilities computer software and applications conference. pp. 979- 984 ,(2008) , 10.1109/COMPSAC.2008.123