• Home
  • Search
  • Runtime Analysis and Instrumentation for Securing Software
  • https://doi.org/10.1007/978-3-642-16612-9_6Copy DOI Icon

Runtime Analysis and Instrumentation for Securing Software

  • Jan 1, 2010
  • R Sekar
Show More
  • Abstract
  • Literature Map
  • Similar Papers
Abstract

The past decade has witnessed an explosive increase in the scale, intensity and sophistication of cyber attacks. While software vendors have significantly increased their efforts on security, they are almost always playing catch up. As a result, security-conscious organizations and individuals have come to expect their system administrators to deploy an array of tools and techniques to stay a step ahead of the hackers. While developer-oriented security tools rely mainly on static analysis, runtime analysis and policy enforcement are the mechanisms of choice in administrator-oriented tools. Runtime techniques offer increased automation and precision over static analysis, thus addressing the needs of administrators who don't have the time or resources needed to acquire extensive knowledge about the internals of a software system. In this talk, I will begin by summarizing some of the significant advances that have been achieved in the past few years in the context of software vulnerability mitigation, including buffer overflow defenses, and more recently, the impressive results that have been achieved using dynamic information-flow analysis for blocking the most popular exploits today, including SQL and command injection and cross-site scripting. I will then proceed to describe dynamic analysis and enforcement techniques aimed at another high-profile security problem faced today, namely, malware defense. Our initial target in this regard has been on dynamic analysis techniques for extracting high-level models of program behavior. These models could be used in a variety of applications such as intrusion detection, vulnerability analysis and security policy verification. More recently, interesting advances have been made in the context of security policy development, where a combination of static and dynamic analysis techniques have been developed to synthesize low-level, enforceable policies that achieve a high-level goal such as protecting system integrity. Finally, I will conclude the talk with a discussion of some research opportunities and challenges in software security.

Similar Papers
  • Dissertation

Data flow and heap analysis with application to privilege escalation vulnerability scanning and software theft detection

  • Jan 01, 2013
  • Ping-Fai Chan
  • PDF
  • Research Article
  • Citations67

Malware Classification Using Probability Scoring and Machine Learning

  • Jan 01, 2019
  • IEEE Access
  • Di Xue +4
  • Conference Article

Fourth international workshop on dynamic analysis (WODA 2006)

  • May 28, 2006
  • Neelam Gupta +1
  • Conference Article
  • Citations77

Integrating Static and Dynamic Analysis for Detecting Vulnerabilities

  • Jan 01, 2006
  • Ashish Aggarwal +1
  • Research Article
  • Citations11

Malware Classification Framework for Dynamic Analysis using Information Theory

  • Feb 01, 2017
  • Indian Journal of Science and Technology
  • Ehsan Moshiri +3
  • Conference Article
  • Citations38

Precise Dynamic Impact Analysis with Dependency Analysis for Object-oriented Programs

  • Aug 01, 2007
  • Lulu Huang +1
  • Conference Article
  • Citations61

Program slicing enhances a verification technique combining static and dynamic analysis

  • Mar 26, 2012
  • Omar Chebaro +3
  • Book Chapter
  • Citations2

Formal Framework for Reasoning About the Precision of Dynamic Analysis

  • Jan 01, 2020
  • Mila Dalla Preda +2
  • Research Article
  • Citations120

Detecting Cryptomining Malware: a Deep Learning Approach for Static and Dynamic Analysis

  • Jan 21, 2020
  • Journal of Grid Computing
  • Hamid Darabian +6
  • Book Chapter
  • Citations1

Toward an Execution Trace Standard: An MDE Approach

  • Jan 01, 2023
  • Claudia Pereira +2
  • Research Article

Integrated Analysis of Malicious Software: Insights from Static and Dynamic Perspectives

  • Nov 10, 2025
  • Journal of Cybersecurity and Privacy
  • Maria-Mădălina Andronache +2
  • Conference Article
  • Citations8

How dangerous is your Android app? An evaluation methodology

  • Jan 01, 2014
  • Andrea Atzeni +4
  • Book Chapter
  • Citations4

Malware Detection Kit for Malware Analysis of Big Data

  • Jan 01, 2021
  • T Sree Lakshmi +2
  • Conference Article
  • Citations16

Boosting static analysis accuracy with instrumented test executions

  • Aug 18, 2021
  • Tianyi Chen +2
  • Research Article
  • Citations2

Static and dynamic analyses for the exergetic, exergoeconomic and environmental assessment of a high-performance building

  • Jan 01, 2018
  • International Journal of Exergy
  • M Pinar Mengüç +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.