OpenOSC: Open Source Object Size Checking Library With Built-in Metrics

Yongkui Han, Pankil Shah, Van Nguyen, Ling Ma, Richard Livingston · 2019

OpenOSC provides value to software development in detecting destination buffer overruns and source buffer over-reads. OpenOSC is presented as open, extensible, object size checking (OSC) library written in C that integrates into most Linux distribution components through hardening flags. It is quite similar to FORTIFY-SOURCE [1] [2] and can complement or replace it in most cases. Like FORTIFY-SOURCE, OpenOSC uses compiler built-in functions [3] in its implementation. The facility also offers some advantages over FORTIFY-SOURCE for compiler and security researchers. Additionally it can be extended to cover more data movement functions such as SafeC library functions. OpenOSC has built-in OSC metrics support, which provides detailed information on OSC coverage. We present a few open source components compiled with OpenOSC as a means to demonstrate the utility of OpenOSC. The effectiveness of three compilers (GCC, CLANG, and ICC) is evaluated and compared. Our results summarize coverage capabilities of these compilers and provide the details on exactly where a compiler might be able to improve its effectiveness. This OpenOSC metric report can be used by product owners to understand where risk remains in the application, where the owners could focus secure code reviews or even targeted SafeC [4] [5] recoding for these calls.

Read the paper · More papers on PaperTik