An Buffer Overflow Automatic Detection Method Based on Operation Semantic

Zhao Zhao, Dong-fan, Liu ., Lei Lei · 中国邮电高校学报:英文版 · 2005

Buffer overflow is the most dangerous attack method that can be exploited. According to the statistics of Computer Emergency Readiness Team(CERT), buffer overflow accounts for 50% of the current software vulnerabilities, and this ratio is going up. Considering a subset of C language, Mini C, this paper presents an abstract machine model that can realize buffer overflow detection, which is based on operation semantic. Thus the research on buffer overflow detection can be built on strict descriptions of operation semantic. Not only the correctness can be assured, but also the system can be realized and extended easily.

Read the paper · More papers on PaperTik