A First Step Towards Automated Detection of Buffer Overrun Vulnerabilities.

David Wagner, Jeffrey S. Foster, Eric Brewer, Alex Aiken · 2000

We describe a new technique for finding potential buffer overrun vulnerabilities in security-critical C code. The key to success is to use static analysis: we formulate detection of buffer overruns as an integer range analysis problem. One major advantage of static analysis is that security bugs can be eliminated before code is deployed. We have implemented our design and used our prototype to find new remotely-exploitable vulnerabilities in a large, widely deployed software package. An earlier hand audit missed these bugs. 1. Introduction Buffer overrun vulnerabilities have plagued security architects for at least a decade. In November 1988, the infamous Internet worm infected thousands or tens of thousands of network-connected hosts and fragmented much of the known net [17]. One of the primary replication mechanisms was exploitation of a buffer overrun vulnerability in the fingerd daemon. Since then, buffer overruns have been a serious, continuing menace to system security. If any...

Read the paper · More papers on PaperTik