• Home
  • Search
  • BOFT: Exploitable Buffer Overflow Detection by Information Flow Tracking
  • Cite Icon8
  • https://doi.org/10.23919/date51398.2021.9474045Copy DOI Icon

BOFT: Exploitable Buffer Overflow Detection by Information Flow Tracking

  • Feb 1, 2021
  • Muhammad Monir Hossain +3 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Buffer overflow is one of the most critical software vulnerabilities with numerous functional and security impacts on memory boundaries and program calls. An exploitable buffer overflow, which can be directly or indirectly triggered through external user domain inputs, is of a greater concern because it can be misused during run-time for adversarial intention. Although some existing tools offer buffer overflow detection to certain extents, there are major limitations, such as, poor detection coverage and ad-hoc/manual verification efforts due to inadequate predefined executions for static analysis and substantially large input subspace for dynamic verification. In this paper, to provide program verification in static time with high detection coverage, we propose an automated framework for Exploitable Buffer Overflow Detection by Information Flow Tracking (BOFT). We achieve this goal following three steps - first, BOFT analyzes the usage of arrays, pointers, and vulnerable application programming interface (APIs) in the program code and automatically inserts assertions required for buffer overflow detection. Second, BOFT instruments the program with taints for direct and indirect information flow tracking using an extensive set of formal expressions. Finally, it symbolically analyzes the instrumented code for maximum coverage and provides the list of exploitable buffer overflow vulnerabilities. BOFT is evaluated on standard benchmarks from SAMATE Juliet Test Suite (NIST) with a successful detection of ~94.87% (minimum) of exploitable buffer overflows with zero false positives.

Similar Papers
  • Conference Article
  • Citations2

CSOD: Context-Sensitive Overflow Detection

  • Feb 01, 2019
  • Hongyu Liu +4
  • Conference Article
  • Citations38

BovInspector: automatic inspection and repair of buffer overflow vulnerabilities

  • Aug 25, 2016
  • Fengjuan Gao +2
  • Research Article
  • Citations3

Hardware information flow tracking based on lightweight path awareness

  • Aug 22, 2024
  • Computers & Security
  • Haodong Sun +4
  • Research Article

Automatic Vulnerability Detection in Tizen Applications with Dynamic Symbolic Execution

  • Feb 09, 2023
  • International Journal of Information and Communication Sciences
  • Sobhan Safdarian +2
  • Conference Article
  • Citations1

Obtaining Fuzzing Results with Different Timeouts

  • Apr 01, 2022
  • Wenxi Zhang
  • Conference Article
  • Citations50

Improving network applications security

  • Jun 25, 2005
  • Concettina Del Grosso +4
  • Research Article
  • Citations110

Analysis and assessment of a knowledge based smart city architecture providing service APIs

  • May 06, 2017
  • Future Generation Computer Systems
  • C Badii +5
  • Research Article
  • Citations12

Auditing buffer overflow vulnerabilities using hybrid static–dynamic analysis

  • Apr 01, 2016
  • IET Software
  • Bindu Madhavi Padmanabhuni +1
  • Research Article
  • Citations12

Enhancing detection coverage in untargeted metabolomics analysis by solid-phase extraction on-line coupled to LC-MS/MS.

  • Aug 21, 2015
  • ELECTROPHORESIS
  • Mónica Calderón‐Santiago +2
  • Conference Article
  • Citations9

Real-Time Detection of Malicious Behavior in Android Apps

  • Aug 01, 2016
  • Zhenyu Ni +4
  • Conference Article

Buffer Overflow Fuzzing Guided by Directed Identification Metric

  • Dec 05, 2025
  • Xiamin Guo +2
  • Conference Article
  • Citations43

Multi-variant Program Execution: Using Multi-core Systems to Defuse Buffer-Overflow Vulnerabilities

  • Jan 01, 2008
  • Babak Salamat +5
  • Conference Article
  • Citations5

Intelligent code analyzer for online course management system

  • Jan 01, 2005
  • Jong-Yih Kuo +1
  • Book Chapter

MySQL Programming

  • Jan 01, 2004
  • Jon Stephens +1
  • Research Article

Leaving the Business Security Burden to LiSEA: A Low-Intervention Security Embedding Architecture for Business APIs

  • Oct 27, 2023
  • Applied Sciences
  • Hang Li +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.