Eliminating Insecure Uses of C Library Functions

Raphael Tawil · Repository for Publications and Research Data (ETH Zurich) · 2012

Many C programs, especially legacy programs, still use insecure functions, for example functions like gets(), that are inherently insecure.Other functions lack bounds checking or important security checks.Despite the existence of operating systemlevel defenses that make use of techniques such as data execution prevention, and address space layout randomization, which reduce the risk of control-flow hijack attacks, greater assurances of security can be obtained by simply not using these functions in the first place.The goal of this thesis is to improve the security of software by discovering and either automatically eliminating calls to these functions at compile-time, or providing a secure wrapper function for them, which carries out the necessary security checks at runtime.This is done with the means of a compiler extension, and is therefore completely transparent to the programmer.When evaluating our compiler, we have seen that it successfully prevented against a variety of attacks that exploited vulnerabilities posed by the usage of insecure C library functions.Additionally, we have seen that our compiler was able to replace calls to insecure functions at compile-time with a good success rate.With regards to performance, we have seen that for some micro-benchmarks, when compiled with our compiler, they run significantly slower.However, when benchmarking a real-world application, no significant performance degradation was observed.

Read the paper · More papers on PaperTik