Analyzing Vulnerable Software Code Using Dynamic Taint and SMT Solver
Sungho Kim, Yongsu Park · 정보과학회 컴퓨팅의 실제 논문지 · 2015
?????? ????? ?? ???? ???? ??? ??? ???? ??. ????? ???? ????? ????? ???? ?? ?? ?? ????? ?? ? ??? ??? ??? ????. ???? ???? ??, ????? ?? ??? ???? ??? ??? ??? ????? ???? ?? ??? ?? ?? ???? ?????. ??, ? ????? ?????? ?? ???? ?? ?? ???? ?? ?? ??? ????. ?? ??? ??, ????? ? ?? ?? ?? ???? ?????? ??? ??? ??? ?? ?? ??? ??. ??, ?? ?? ??? ?? ?? ???? ?? ?? ???? ???? ??? ???? ????? ??? ??? ?? ???? ????. ??? ?? ???? ????? ?? SMT ???? ???? ?? ???? ??? ? ?? ?? ?? ???. ?? ??? ?? ??? ??, ? ?????? ???? ??? ? ?? ???? ?? ?? 6?? ???. As software grows more complex, it contains more bugs that are not recognized by developers. Attackers can then use exploitable bugs to penetrate systems or spread malicious code. As a representative method, attackers manipulated documents or multimedia files in order to make the software engage in unanticipated behavior. Recently, this method has gained frequent use in A.P.T. In this paper, an automatic analysis method to find software security bugs was proposed. This approach aimed at finding security bugs in the software which can arise from input data such as documents or multimedia. Through dynamic taint analysis, how input data propagation to vulnerable code occurred was tracked, and relevant instructions in relation to input data were found. Next, the relevant instructions were translated to a formula and vulnerable input data were found via the formula using an SMT solver. Using this approach, 6 vulnerable codes were found, and data were input to crash applications such as HWP and Gomplayer.