Integer overflow vulnerabilities detection in software binary code

Roman Demidov, Alexander Pechenkin, Peter D. Zegzhda · 2017

In this paper1 we propose a new approach to detect integer overflow vulnerabilities in executable x86-architecture code. The approach is based on symbolic execution of the code and the dual representation of memory. We build truncated control flow graph, based on the machine code. Layers in that graph are checked for the feasibility of vulnerability conditions. The proposed methods were implemented and experimentally tested on executable code.

Read the paper · More papers on PaperTik