Generation of multiple code variants through automatic buffer size extension
Ernesto García Grabwosky · 2016
El presente documento es la culminacion de un proyecto de desarrollo de un software cuyo proposito es generar multiples versiones de un codigo fuente recibido como entrada. Las nuevas versiones generadas se diferenciaran de la original en el tamano de los diferentes buffers definidos en el codigo fuente original. Al ser ejecutada, la herramienta permitira seleccionar entre diferentes opciones que definen el modo en que las diferentes fases del proceso seran realizadas. El nucleo de la herramienta esta compuesto por un parser que fue desarrollado especificamente para detectar declaraciones de buffers y accesos a estos a lo largo de un codigo fuente. Este parser ha sido generado utilizando la herramienta JavaCC, la cual es capaz de generar automaticamente un parser en lenguaje Java, recibiendo como entrada una gramatica LL(k) definida por el desarrollador. Puesto que la funcionalidad basica del parser no es suficiente para completar el fin del proyecto, la salida de JavaCC ha sido personalizada y extendida para tal proposito. Es importante mencionar que la complejidad de este proyecto no resude en la cantidad de piezas que conforman el sistema sino en la extension del lenguaje de programacion que se va a procesar. Por tanto, las limitaciones del prototipo vienen directamente de la gramatica utilizada. Esta gramatica ha sido disenada de forma especifica para este proyecto con el fin de procesar un subconjunto del lenguaje C, lo que quiere decir que algunos programas que podrian ser procesados por un compilador de C estandar podrian causar errores al ser procesados por el programa generado en este proyecto. La motivacion de crear esta herramienta viene de la necesidad generada por la investigacion de Berk Bekiroglou, un estudiante de doctorado del Illinois Institute of Technology que busca mejorar la supervivencia de cualquier software, ante diferentes tecnicas maliciosas mediante la generacion de diferentes versiones del mismo tal que la vulnerabilidad en el mapa de memoria de una version no este presente en sus versiones hermanas.--ABSTRACT--The present document is the culmination of a software development project whose main goal is to generate new versions of a given source code. These new versions will differ from the original versions in the size of the different buffers that might have been defined in the original code. When the tool is executed, it will allow the user to choose among different options that define how the different phases of the new code generation process will be performed. The core of the tool is composed by a parser that was developed specifically to detect buffer declarations and accesses among the source code. This parser has been generated using the tool JavaCC which is able to automatically generate the parser code given a LL(k) grammar defined by the developer. Since the functionality of a basic parser is not enough to perform the work required to complete the goal of the project, it has been customized and extended for that purpose. It is important to mention that the complexity of this project does not reside in the amount of different pieces that conform the system, but in the extension of the target programming language. The resulting software is a prototype with limitations that come from the grammar defined to generate the parser. This grammar was designed to handle a subset of the programming language C, a source code file that may contain aspects of the language that are supported by any compiler but not by the tool, will produce different errors when the program is executed using this file. The motivation to create this tool comes from a neccesity generated by Berk Bekiroglou’s research. Berk is a PhD candidate in the Illinois Institute of Technology who is trying to improve the survaivability of software programs by generating different versions of it. These different versions would have different memory maps that would avoid sharing the same vulnerabilities when facing certain tyoes of memory attacks.