Efficient Identification of Race Condition Vulnerability in C code by Abstract Interpretation and Value Analysis
Mehran Yousaf, Muddassar Azam Sindhu, Muhammad Hassan Arif, Shafiq ur Réhman · 2021
The increased usage of information and communication technologies has changed the way industries look at things. This development of technology in terms of software utilization has resulted in various security vulnerabilities such as injection, data disclosure, authentication, and access control concerns. When working with concurrent applications, race conditions can trigger a number of these vulnerabilities. Formal approaches have been developed to detect the race condition vulnerability in the literature. Existing approaches for detecting race conditions have few drawbacks that includes static checkers’ inability to analyze the uninterpreted programs, and minimal exploration of race condition types. Due to these weaknesses static checkers produce a large number of false alarms. This study proposes an algorithm AIT for analysis of uninterpreted programs based on a formal static analysis technique called Abstract Interpretation (AI). It also proposes the T2RC and Sync RC algorithms for race condition detection. The proposed approach is validated using Juliet and Data Race Bench data sets. The proposed method yields an average accuracy of 84% and produces very few false alarms. Additionally, it not only handles uninterpreted programs, but also analyzes for a wider range of Race Conditions thus performing better than other comparable approaches.