• Home
  • Search
  • Proving memory safety of floating-point computations by combining static and dynamic program analysis
  • Open Access IconOpen Access
  • Cite Icon33
  • https://doi.org/10.1145/1831708.1831710Copy DOI Icon

Proving memory safety of floating-point computations by combining static and dynamic program analysis

  • Jul 12, 2010
  • Patrice Godefroid +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Whitebox fuzzing is a novel form of security testing based on dynamic symbolic execution and constraint solving. Over the last couple of years, whitebox fuzzers have found many new security vulnerabilities (buffer overflows) in Windows and Linux applications, including codecs, image viewers and media players. Those types of applications tend to use floating-point instructions available on modern processors, yet existing whitebox fuzzers and SMT constraint solvers do not handle floating-point arithmetic. Are there new security vulnerabilities lurking in floating-point code?A naive solution would be to extend symbolic execution to floating-point (FP) instructions (months of work), extend SMT solvers to reason about FP constraints (months of work or more), and then face more complex constraints and an even worse path explosion problem. Instead, we propose an alternative approach, based on the rough intuition that FP code should only perform memory safe data-processing of the payload of an image or video file, while the non-FP part of the application should deal with buffer allocations and memory address computations, with only the latter being prone to buffer overflows and other security critical bugs. Our approach combines (1) a lightweight local path-insensitive may static analysis of FP instructions with (2) a high-precision whole-program path-sensitive must dynamic analysis of non-FP instructions. The aim of this combination is to prove memory safety of the FP part of each execution and a form of non-interference between the FP part and the non-FP part with respect to memory address computations.We have implemented our approach using two existing tools for, respectively, static and dynamic x86 binary analysis. We present preliminary results of experiments with standard JPEG, GIF and ANI Windows parsers. For a given test suite of diverse input files, our mixed static/dynamic analysis is able to prove memory safety of FP code in those parsers for a small upfront static analysis cost and a marginal runtime expense compared to regular dynamic symbolic execution.

Similar Papers
  • PDF
  • Research Article
  • Citations6

Комбинирование динамического символьного исполнения, статического анализа кода и фаззинга

  • Jan 01, 2018
  • Proceedings of the Institute for System Programming of the RAS
  • A.Yu Gerasimov +5
  • Research Article

Automatic Vulnerability Detection in Tizen Applications with Dynamic Symbolic Execution

  • Feb 09, 2023
  • International Journal of Information and Communication Sciences
  • Sobhan Safdarian +2
  • Conference Article
  • Citations58

Backward-Bounded DSE: Targeting Infeasibility Questions on Obfuscated Codes

  • May 01, 2017
  • Sebastien Bardin +2
  • Book Chapter
  • Citations1

Algorithm Selection for Dynamic Symbolic Execution: A Preliminary Study

  • Jan 01, 2021
  • Roberto Amadini +4
  • Conference Article
  • Citations124

Automatic partial loop summarization in dynamic test generation

  • Jul 17, 2011
  • Patrice Godefroid +1
  • Conference Article
  • Citations2

Smart Parser for Identifying and Detecting Insecure Functions

  • Oct 01, 2017
  • Esraa Al-Shammari +2
  • Research Article
  • Citations12

Auditing buffer overflow vulnerabilities using hybrid static–dynamic analysis

  • Apr 01, 2016
  • IET Software
  • Bindu Madhavi Padmanabhuni +1
  • Book Chapter
  • Citations2

Formal Framework for Reasoning About the Precision of Dynamic Analysis

  • Jan 01, 2020
  • Mila Dalla Preda +2
  • Conference Article
  • Citations10

Casr-Cluster: Crash Clustering for Linux Applications

  • Dec 01, 2021
  • Georgy Savidov +1
  • Conference Article
  • Citations111

MultiSE: multi-path symbolic execution using value summaries

  • Aug 30, 2015
  • Koushik Sen +3
  • Conference Article
  • Citations115

Model-based whitebox fuzzing for program binaries

  • Aug 25, 2016
  • Van-Thuan Pham +2
  • PDF
  • Research Article
  • Citations1

Error detection in binary code with dynamic symbolic execution

  • Jan 01, 2022
  • Proceedings of the Institute for System Programming of the RAS
  • Alexey Vishnyakov +2
  • Book Chapter
  • Citations1

Verification, Testing and Statistics

  • Jan 01, 2009
  • Sriram K Rajamani
  • Conference Article
  • Citations7

Numerical Accuracy Improvement by Interprocedural Program Transformation

  • Jun 12, 2017
  • Nasrine Damouche +2
  • Conference Article
  • Citations38

BovInspector: automatic inspection and repair of buffer overflow vulnerabilities

  • Aug 25, 2016
  • Fengjuan Gao +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.