• Home
  • Search
  • CSOD: Context-Sensitive Overflow Detection
  • Cite Icon2
  • https://doi.org/10.1109/cgo.2019.8661198Copy DOI Icon

CSOD: Context-Sensitive Overflow Detection

  • Feb 1, 2019
  • Hongyu Liu +4 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Buffer overflow is possibly the most well-known memory issue. It can cause erratic program behavior, such as incorrect outputs and crashes, and can be exploited to issue security attacks. Detecting buffer overflows has drawn significant research attention for almost three decades. However, the prevalence of security attacks due to buffer overflows indicates that existing tools are still not widely utilized in production environments, possibly due to their high performance overhead or limited effectiveness. This paper proposes CSOD, a buffer overflow detection tool designed for the production environment. CSOD proposes a novel context-sensitive overflow detection technique that can dynamically adjust its detection strategy based on the behavior of different allocation calling contexts, enabling it to effectively detect overflows in millions of objects via four hardware watchpoints. It can correctly report root causes of buffer over-writes and over-reads, without any additional manual effort. Furthermore, CSOD only introduces 6.7% performance overhead on average, which makes it appealing as an always-on approach for production software.

Similar Papers
  • Conference Article
  • Citations8

BOFT: Exploitable Buffer Overflow Detection by Information Flow Tracking

  • Feb 01, 2021
  • Muhammad Monir Hossain +3
  • Conference Article
  • Citations38

BovInspector: automatic inspection and repair of buffer overflow vulnerabilities

  • Aug 25, 2016
  • Fengjuan Gao +2
  • Research Article
  • Citations36

Cruiser

  • Jun 04, 2011
  • ACM SIGPLAN Notices
  • Qiang Zeng +2
  • Book Chapter
  • Citations2

Efficient and Effective Buffer Overflow Protection on ARM Processors

  • Jan 01, 2010
  • Raoul Strackx +3
  • Research Article
  • Citations4

IReplayer: in-situ and identical record-and-replay for multithreaded applications

  • Jun 11, 2018
  • ACM SIGPLAN Notices
  • Hongyu Liu +4
  • Conference Article
  • Citations35

Efficient soft error protection for commodity embedded microprocessors using profile information

  • Jun 12, 2012
  • Daya Shanker Khudia +2
  • Research Article
  • Citations21

Efficient soft error protection for commodity embedded microprocessors using profile information

  • May 18, 2012
  • ACM SIGPLAN Notices
  • Daya Shanker Khudia +2
  • Conference Article
  • Citations16

Exploiting on-chip power management for side-channel security

  • Mar 01, 2018
  • Arvind Singh +5
  • Conference Article
  • Citations50

Improving network applications security

  • Jun 25, 2005
  • Concettina Del Grosso +4
  • Conference Article
  • Citations29

TAPE

  • Jun 20, 2005
  • Hassan Chafi +7
  • Research Article
  • Citations4

SUPnP: Secure Access and Service Registration for UPnP-Enabled Internet of Things

  • Feb 13, 2021
  • IEEE Internet of Things Journal
  • Golam Kayas +3
  • Conference Article
  • Citations2

Automatic Sound Static Analysis for Integration Verification of AUTOSAR Software

  • Apr 11, 2023
  • SAE technical papers on CD-ROM/SAE technical paper series
  • Daniel Kaestner +5
  • Conference Article
  • Citations43

Multi-variant Program Execution: Using Multi-core Systems to Defuse Buffer-Overflow Vulnerabilities

  • Jan 01, 2008
  • Babak Salamat +5
  • PDF
  • Research Article
  • Citations5

A New Analysis Approach Incorporated with Analytic Hierarchy Process for The Software Application in A Multiple Tiers Environment

  • Dec 24, 2019
  • European Journal of Electrical Engineering and Computer Science
  • Hoo Meng Wong +1
  • Research Article
  • Citations15

The development of an efficient checkpointing facility exploiting operating systems services of the GENESIS cluster operating system

  • Sep 19, 2003
  • Future Generation Computer Systems
  • J.T Rough +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.