A Methodology for Security Vulnerability Assessment Process on Binary Code
Seong Oun Hwang · 한국인터넷방송통신학회 논문지 · 2012
Abstract Cyber attacks have rapidly increased by exploiting the underlying vulnerabilities in the target software. However, identifying and correcting these vulnerabilities are extremely difficult and time consuming tasks. To address these problems efficiently, we propose a systematic methodology for security vulnerability assessment process on binary code in the paper. Specifically, we first classified the existing vulnerabilities based on whether the target software run in a Web environment and features of the software. Based on the classification, we determined the list and scope of the vulnerabilities. As our future research direction, we need to further refine and validate our methodology. Key Words : Security Vulnerability, Security Analysis, Fuzzing, Tainting, Cyber Attack * 정회원, 홍익대학교 컴퓨터정보통신공학과 접수일자: 2012년 8월 30일, 수정완료 : 2012년 9월 30일게재확정일자: 2012년 10월 12일Received: 30 August 2012 / Revised: 30 September 2012 /Accepted: 12 October 2012 * Corresponding Author: [email protected]. of Computer & Information Communications Engineering, Hongik University, Korea