Skip to main navigation Skip to search Skip to main content

Executable based vulnerability detection

  • Chaojian Hu
  • , Jia Zhang
  • , Zhoujun Li*
  • , Zhiwei Shi
  • , Yan Zhang
  • *Corresponding author for this work
  • Beihang University
  • China Information Technology Security Evaluation Center

Research output: Contribution to journalArticlepeer-review

Abstract

Since there are semantic differences between a source code and its executable code, analysis of only the source code may miss some vulnerabilities in the executable code. Typical vulnerability patterns were analyzed to design a security vulnerability detection tool to work directly on executables. The system combines static disassembly analysis, dynamic auto-debugging and function based argument injection. The tool successfully found buffer overflow vulnerabilities in both a CVE (common vulnerabilities & exposures) benchmark and two real executables. The results show that this detection method can be used to directly detect security vulnerabilities in executable codes.

Original languageEnglish
Pages (from-to)2176-2180
Number of pages5
JournalQinghua Daxue Xuebao/Journal of Tsinghua University
Volume49
Issue numberSUPPL. 2
StatePublished - Dec 2009

Keywords

  • Argument injection
  • Auto-debug
  • Disassembly analysis
  • Executables
  • Vulnerability detection

Fingerprint

Dive into the research topics of 'Executable based vulnerability detection'. Together they form a unique fingerprint.

Cite this