Binary Vulnerability Exploitability Analysis

Feng-Yi Tang, Chao Feng, Chaojing Tang · 2016

In this paper, we propose reversed taint analysis to dig out the root cause of the vulnerability leading to crash. In order to increase the efficiency, we propose that during the analysis process, we should only taint the EIP register when the crash happens and then trace back to analyze the data and operations, until we find out the influential inputs that can be controlled by the users. In addition, we suggest that only the exploits could confirm exploitable vulnerabilities. To confirm the exploitability, we propose degraded symbolic execution to generate exploits efficiently by only symbolizing the user's input found in the reversed taint analysis to decrease the number of symbolic variables, in other words, decrease the number of path we need to execute. We also discuss how the exploit mitigations of modern operating system affect the judgment on exploitability of vulnerabilities. And we found that the exploitability of a vulnerability should be judged according to the version of operating system and mitigations.

Read the paper · More papers on PaperTik