• Home
  • Search
  • A Value Set Analysis Refinement Approach Based on Conditional Merging and Lazy Constraint Solving
  • Cite Icon9
  • https://doi.org/10.1109/access.2019.2936139Copy DOI Icon

A Value Set Analysis Refinement Approach Based on Conditional Merging and Lazy Constraint Solving

Show More
  • Abstract
  • Highlights & Summary
  • PDF
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Value set analysis is a common static binary program analysis approach. Value set analysis attempts to identify a tight over-approximation of the program state at any given point in the program and can be used to detect vulnerability. Existing memory corruption detection analysis technologies based on value set analysis have a high false positive rate, because value set analysis suffers from a lack of accuracy. We observed that two main sources of imprecision in value set analysis are merge operation and failed branch conditions tracking. In order to address above problems, in this paper, we propose a value set analysis refinement approach based on conditional merging and lazy constraint solving. We propose a variable dependence analysis algorithm to divide program paths into subsets and only merge the states which satisfy the condition that the states are from the same subset, which reduces the imprecision from the merging operation. We collect path predicates as path constraint and solve the path constraint using Satisfiability Modulo Theories (SMT) solver lazily to get a tighter number range of the variable when a variable need be refined, which reduces the imprecision from the failed branch conditions tracking. We implement a prototype system RVSA based on the proposed approach and verify its effectiveness according to experimentation. Compared with state-of-the-art approach, the experimental results demonstrate that the false positive rate is reduced by 12.9%. Furthermore, using our proposed approach, 25 zero-day vulnerabilities are found in the Netgear httpd binary.

Loading PDF

Similar Papers
  • Research Article
  • Citations3

Don’t care in SMT: building flexible yet efficient abstraction/refinement solvers

  • Nov 10, 2009
  • International Journal on Software Tools for Technology Transfer
  • Andreas Bauer +3
  • Conference Article
  • Citations5

Model Synthesis for Communication Traces of System Designs

  • Oct 01, 2021
  • Hao Zheng +4
  • Dissertation
  • Citations7

Finite model finding in satisfiability modulo theories

  • Feb 05, 2014
  • Andrew Joseph Reynolds
  • Book Chapter
  • Citations1

SMT Solvers: Foundations and Applications

  • Jan 01, 2016
  • BjØRner Nikolaj
  • Research Article
  • Citations9

Local Search For Satisfiability Modulo Integer Arithmetic Theories

  • Jul 25, 2023
  • ACM Transactions on Computational Logic
  • Shaowei Cai +2
  • Research Article

Model Checking for Rectangular Hybrid Systems: A Quantified Encoding Approach

  • Jul 14, 2022
  • Electronic Proceedings in Theoretical Computer Science
  • Luan V Nguyen +2
  • Conference Article
  • Citations19

Boosting SMT solver performance on mixed-bitwise-arithmetic expressions

  • Jun 18, 2021
  • Dongpeng Xu +6
  • Research Article
  • Citations9

Extending ACL2 with SMT Solvers

  • Sep 18, 2015
  • Electronic Proceedings in Theoretical Computer Science
  • Yan Peng +1
  • Book Chapter
  • Citations4

Encoding Queues in Satisfiability Modulo Theories Based Bounded Model Checking

  • Jan 01, 2008
  • Tommi Junttila +1
  • Conference Article

Approximating Quantified SMT-Solving with SAT

  • Jun 01, 2011
  • Xianjin Fu +2
  • PDF
  • Research Article
  • Citations5

An Approach for Detecting Feasible Paths Based on Minimal SSA Representation and Symbolic Execution

  • Jun 10, 2021
  • Applied Sciences
  • Abdalla Wasef Marashdih +2
  • Book Chapter
  • Citations46

Symbolic Query Exploration

  • Jan 01, 2009
  • Margus Veanes +3
  • Research Article
  • Citations4

Estimating the Density of States of Boolean Satisfiability Problems on Classical and Quantum Computing Platforms

  • Apr 03, 2020
  • Proceedings of the AAAI Conference on Artificial Intelligence
  • Tuhin Sahai +3
  • Research Article

Verification and Validation of Model-Based Systems Requirements and Design Leveraging Formal Methods to Increase Development Assurance

  • Mar 05, 2024
  • SAE International Journal of Advances and Current Practices in Mobility
  • Craig Mcmillan +9
  • Book Chapter
  • Citations1

A Reduction-Based Approach for Solving Disjunctive Temporal Problems with Preferences

  • Jan 01, 2013
  • Jean-Rémi Bourguet +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.