• Home
  • Search
  • Auditing buffer overflow vulnerabilities using hybrid static–dynamic analysis
  • Cite Icon12
  • https://doi.org/10.1049/iet-sen.2014.0185Copy DOI Icon

Auditing buffer overflow vulnerabilities using hybrid static–dynamic analysis

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Buffer overflow (BOF) vulnerabilities when present in code can be exploited to violate security objectives such as availability, confidentiality and integrity. They make up substantial portion of input manipulation attacks due to their common presence and ease of exploitation. In this study, the authors propose a hybrid approach combining static and dynamic program analysis with machine learning to audit BOFs. Simple rules to generate test data is proposed to confirm some of the vulnerabilities through dynamic analysis. Confirmed cases can be fixed by developers without further verification. Statements whose vulnerability is not confirmed by dynamic analysis are predicted by mining static code attributes. In the authors’ evaluation using standard benchmarks, their best classifier achieved a recall over 93% and accuracy >94%. Dynamic analysis itself confirmed 34% of known vulnerabilities along with reporting six new bugs, thereby reducing by third, otherwise needed manual auditing effort.

Similar Papers
  • Book Chapter
  • Citations2

Formal Framework for Reasoning About the Precision of Dynamic Analysis

  • Jan 01, 2020
  • Mila Dalla Preda +2
  • Conference Article
  • Citations6

Classification of Buffer Overflow Vulnerability Monitors

  • Feb 01, 2010
  • Hossain Shahriar +1
  • Conference Article
  • Citations77

Integrating Static and Dynamic Analysis for Detecting Vulnerabilities

  • Jan 01, 2006
  • Ashish Aggarwal +1
  • Conference Article
  • Citations33

Proving memory safety of floating-point computations by combining static and dynamic program analysis

  • Jul 12, 2010
  • Patrice Godefroid +1
  • Research Article
  • Citations21

A Buffer Overflow Prediction Approach Based on Software Metrics and Machine Learning

  • Mar 03, 2019
  • Security and Communication Networks
  • Jiadong Ren +4
  • Conference Article
  • Citations38

BovInspector: automatic inspection and repair of buffer overflow vulnerabilities

  • Aug 25, 2016
  • Fengjuan Gao +2
  • Dissertation

Data flow and heap analysis with application to privilege escalation vulnerability scanning and software theft detection

  • Jan 01, 2013
  • Ping-Fai Chan
  • PDF
  • Research Article
  • Citations67

Malware Classification Using Probability Scoring and Machine Learning

  • Jan 01, 2019
  • IEEE Access
  • Di Xue +4
  • Conference Article
  • Citations24

Business process recovery for system maintenance — An empirical approach

  • Sep 01, 2009
  • Zhengong Cai +2
  • Conference Article
  • Citations28

Dynamic shape analysis via degree metrics

  • Jun 19, 2009
  • Maria Jump +1
  • Book Chapter

Runtime Analysis and Instrumentation for Securing Software

  • Jan 01, 2010
  • R Sekar
  • Book Chapter
  • Citations1

Verification, Testing and Statistics

  • Jan 01, 2009
  • Sriram K Rajamani
  • Conference Article
  • Citations43

Multi-variant Program Execution: Using Multi-core Systems to Defuse Buffer-Overflow Vulnerabilities

  • Jan 01, 2008
  • Babak Salamat +5
  • Conference Article
  • Citations5

DPAC

  • Dec 09, 2013
  • Yanyan Jiang +2
  • Conference Article

LinkRadar

  • Nov 03, 2019
  • Diandian Gu +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.