• Home
  • Search
  • Integrating Static and Dynamic Analysis for Detecting Vulnerabilities
  • Cite Icon77
  • https://doi.org/10.1109/compsac.2006.55Copy DOI Icon

Integrating Static and Dynamic Analysis for Detecting Vulnerabilities

  • Jan 1, 2006
  • Ashish Aggarwal +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

A secure software demands effective techniques for vulnerability detection during its development cycle. The practice of detecting security flaws before the deployment phase eliminates the risks that vulnerabilities may impose for the company. Static analysis and dynamic analysis techniques offer two complimentary approaches for checking vulnerabilities. Static analysis involves the scanning of source code or binary eliminating the need of executing it. This approach is fast and has no run time overhead. However, static analysis are quite imprecise and generate huge false positives and false negatives. On the other hand, dynamic analysis involves the running of the software. The problem of false positives and negatives is less in case of dynamic analysis because they analyze by running the test cases. But this approach requires large number of test cases to ensure a certain confidence level in detecting security bugs. This paper describes a methodology which integrates the two approaches in a complimentary manner. It adopts the strengths of the two and eliminates their weaknesses. We are currently dealing with buffer overflow vulnerability with pointer aliasing. However the idea can be extended to other vulnerabilities also for e.g memory related errors, race conditions( Time of Check to Time to Use vulnerability), dangling pointer vulnerability, integer errors etc.

Similar Papers
  • PDF
  • Research Article
  • Citations67

Malware Classification Using Probability Scoring and Machine Learning

  • Jan 01, 2019
  • IEEE Access
  • Di Xue +4
  • Research Article
  • Citations28

Memory distortion and sexual trauma: the problem of false negatives and false positives.

  • Oct 01, 1994
  • International Journal of Clinical and Experimental Hypnosis
  • Michael R Nash
  • Conference Article

Poster: Static Analysis of Concurrent Higher-Order Programs

  • May 01, 2015
  • Quentin Stievenart +3
  • Conference Article

The consequences of statistical tests on proxy variables, an application to short-TE as an estimation for MEGA-edited GABA

  • Sep 16, 2025
  • Proceedings on CD-ROM - International Society for Magnetic Resonance in Medicine. Scientific Meeting and Exhibition/Proceedings of the International Society for Magnetic Resonance in Medicine, Scientific Meeting and Exhibition
  • Karl Landheer +2
  • Conference Article
  • Citations8

Condition-Guided Adversarial Generative Testing for Deep Learning Systems

  • Apr 01, 2019
  • Pengcheng Zhang +2
  • Dissertation

Data flow and heap analysis with application to privilege escalation vulnerability scanning and software theft detection

  • Jan 01, 2013
  • Ping-Fai Chan
  • Research Article
  • Citations12

Auditing buffer overflow vulnerabilities using hybrid static–dynamic analysis

  • Apr 01, 2016
  • IET Software
  • Bindu Madhavi Padmanabhuni +1
  • Conference Article
  • Citations61

Program slicing enhances a verification technique combining static and dynamic analysis

  • Mar 26, 2012
  • Omar Chebaro +3
  • Research Article
  • Citations66

Reliability of non-lethal surveillance methods for detecting ranavirus infection

  • Jan 01, 2012
  • Diseases of Aquatic Organisms
  • Mj Gray +2
  • Book Chapter

Runtime Analysis and Instrumentation for Securing Software

  • Jan 01, 2010
  • R Sekar
  • Research Article
  • Citations41

The Effect of Testing Reliability on Visual Field Sensitivity in Normal Eyes: The Singapore Chinese Eye Study

  • Aug 30, 2017
  • Ophthalmology
  • Nicholas Y.Q Tan +7
  • Research Article
  • Citations59

Static analysis of source code security: Assessment of tools against SAMATE tests

  • Feb 13, 2013
  • Information and Software Technology
  • Gabriel Díaz +1
  • Conference Article
  • Citations9

Exploiting Type Hints in Method Argument Names to Improve Lightweight Type Inference

  • May 01, 2017
  • Nevena Milojkovic +2
  • Book Chapter
  • Citations2

Formal Framework for Reasoning About the Precision of Dynamic Analysis

  • Jan 01, 2020
  • Mila Dalla Preda +2
  • Conference Article
  • Citations16

Boosting static analysis accuracy with instrumented test executions

  • Aug 18, 2021
  • Tianyi Chen +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.