Back to Search Start Over

格式化字符串漏洞自动检测与测试用例生成.

Authors :
黄钊
黄曙光
邓兆琨
黄晖
Source :
Application Research of Computers / Jisuanji Yingyong Yanjiu. Aug2019, Vol. 36 Issue 8, p2464-2468. 5p.
Publication Year :
2019

Abstract

The format string vulnerability is a kind of software vulnerability which has high risk and wide impact. Currently, there are many limitations of vulnerability detection method, such as high degree of artificial dependence, high false positive rate, single detection model and failing to consider the characteristics of the format string vulnerability fully. To solve above problems, this paper analyzed the format string vulnerability. Based on symbolic execution, the paper designed and produced a way to detect formatted string vulnerability and generate test cases automatically. This method detected the existence of the format string vulnerability in Linux binary program automatically and determined whether it could lead to harm, which allowed attackers to read or write arbitrary memory. Meanwhile it generated stable and effective test cases. [ABSTRACT FROM AUTHOR]

Details

Language :
Chinese
ISSN :
10013695
Volume :
36
Issue :
8
Database :
Academic Search Index
Journal :
Application Research of Computers / Jisuanji Yingyong Yanjiu
Publication Type :
Academic Journal
Accession number :
137841939
Full Text :
https://doi.org/10.19734/j.issn.1001-3695.2018.01.0168