Binary Code Security: The Source of Vulnerability, Exploitation and Mitigation Techniques

Zhijian Huang, X. S. Qin, Shuxin Sun, Long Zhang, Hongquan Xu, Pengfei Hu · 2024

Binary codes are executable files on operating systems, containing instructions and data compiled from source codes written to perform computational tasks. Due to incorrect usage of pointers and unrestricted memory access, vulnerabilities arise in binary codes that can be exploited to gain system-level control, execute arbitrary code, and leak private data, thereby damaging digital assets. Consequently, protecting binary code from vulnerability exploitation is essential for system security. In this paper, we offer a literature review of the current state of binary code security research, focusing on vulnerabilities. We analyze the origins of vulnerabilities stemming from unsafe programming languages and unsafe programming practices. Based on exploitation methods, we categorize attacks into control-flow hijacking, non-control data attacks, and side-channel attacks, providing detailed illustrations for each. We also conduct a thorough analysis of vulnerability mitigation methods, including vulnerability patching, secure code development, memory sanitization, and exploit mitigation. By presenting this systematic summary, we aim to provide effective defense strategies and technologies for information security and to advance research in binary code security.

Read the paper · More papers on PaperTik