Security Patches Analyzing Through Disassemble Technology
Ming Zeng, Pla Information · 2006
Software vulnerability is a primary cause of information system insecurity. Patches are always used by software vendors to amend mistakes in software-system which causes safety problems. Patches analyzing technology tries to find out details of the vulnerability that has been corrected. To avoid this, software vendors refused to offer details of patches to the public, usually only binary versions before and after patching is provided. This drives researchers to analyze patches through binary comparing. A method based on disassemble technology to do patches comparing is presented in this article. Following crucial technologies are discussed in detail: 1)function reorganization and description in binaries.2)For a function in one binary version, how to find its peer in another version with the same function.3)how to remove difference caused by compiler. A framework implementing the described method is presented. As a practical example, a security update that fixes a crucial vulnerability in Internet Explore is analyzed.