跳到主要导航 跳到搜索 跳到主要内容

File parsing vulnerability detection with symbolic execution

  • Chaojian Hu*
  • , Zhoujun Li
  • , Jinxin Ma
  • , Tao Guo
  • , Zhiwei Shi
  • *此作品的通讯作者
  • Beihang University
  • Security Evaluation Center

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Symbolic execution simulates program execution by replacing concrete values with symbolic variables for inputs. It could be used in software behavior analysis, vulnerability detection and software security assessment. In this paper, we analyze the path explosion problem encountered in vulnerability detection with the state-of-the-art symbolic execution technology for large scale file parsing programs. We also propose 4 alleviations to ease the problem, i.e. loop controlling, irrelevant path elimination, path selecting and parallel symbolic execution. Based on these alleviations, we implemented a prototype tool to detect file parsing vulnerability in large scale programs automatically, and evaluate it with a suit of benchmarks chosen from open source programs. Our tool detected not only all reported vulnerabilities of memory overflow in the benchmarks, but also some unreported vulnerabilities. The evaluation results show these alleviations could effectively ease the path explosion problem while analyzing large scale file parsing programs.

源语言英语
主期刊名Proceedings - IEEE 6th International Symposium on Theoretical Aspects of Software Engineering, TASE 2012
135-142
页数8
DOI
出版状态已出版 - 2012
活动IEEE 6th International Symposium on Theoretical Aspects of Software Engineering, TASE 2012 - Beijing, 中国
期限: 4 7月 20126 7月 2012

出版系列

姓名Proceedings - IEEE 6th International Symposium on Theoretical Aspects of Software Engineering, TASE 2012

会议

会议IEEE 6th International Symposium on Theoretical Aspects of Software Engineering, TASE 2012
国家/地区中国
Beijing
时期4/07/126/07/12

学术指纹

探究 'File parsing vulnerability detection with symbolic execution' 的科研主题。它们共同构成独一无二的学术指纹。

引用此