Vulnerability Detection using Static Taint Analysis

Nirupama Talele · 2017

Increase in internet of things has consequently made ubiquitous the embedded devices that deal with security critical data. The embedded devices generally have proprietary firmware with limited access to its code and documentation. In this work we look at the binaries lifted from these firmware, use a third party tool to decompile them and then analyze them for security flaws. We introduce a Context sensitive, Flow sensitive and selective field sensitive Static Taint Analysis Tool CF-STAT . CF-STAT provides mechanism to semi automatically detect vulnerability in a given program. The vulnerabilities like authentication bypass, hard coded backdoor and user input based undesirable program launching can be detected using the data flow analysis feature provided by CF-STAT . We semi-automatically analyze over 50 binaries using CF-STAT to determine the presence or absence of malice in these programs.

Read the paper · More papers on PaperTik