DocumentCode :
2353977
Title :
A combinatorial approach to detecting buffer overflow vulnerabilities
Author :
Wang, Wenhua ; Lei, Yu ; Liu, Donggang ; Kung, David ; Csallner, Christoph ; Zhang, Dazhi ; Kacker, Raghu ; Kuhn, Rick
Author_Institution :
Dept. of Comput. Sci. & Eng., Univ. of Texas at Arlington, Arlington, TX, USA
fYear :
2011
fDate :
27-30 June 2011
Firstpage :
269
Lastpage :
278
Abstract :
Buffer overflow vulnerabilities are program defects that can cause a buffer to overflow at runtime. Many security attacks exploit buffer overflow vulnerabilities to compromise critical data structures. In this paper, we present a black-box testing approach to detecting buffer overflow vulnerabilities. Our approach is motivated by a reflection on how buffer overflow vulnerabilities are exploited in practice. In most cases the attacker can influence the behavior of a target system only by controlling its external parameters. Therefore, launching a successful attack often amounts to a clever way of tweaking the values of external parameters. We simulate the process performed by the attacker, but in a more systematic manner. A novel aspect of our approach is that it adapts a general software testing technique called combinatorial testing to the domain of security testing. In particular, our approach exploits the fact that combinatorial testing often achieves a high level of code coverage. We have implemented our approach in a prototype tool called Tance. The results of applying Tance to five open-source programs show that our approach can be very effective in detecting buffer overflow vulnerabilities.
Keywords :
program testing; security of data; Tance; black-box testing approach; buffer overflow vulnerability detection; combinatorial testing; software testing technique; Arrays; Buffer overflow; Correlation; Payloads; Security; Software; Testing; Buffer Overflow Vulnerability; Security Testing; Software Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems & Networks (DSN), 2011 IEEE/IFIP 41st International Conference on
Conference_Location :
Hong Kong
ISSN :
1530-0889
Print_ISBN :
978-1-4244-9232-9
Electronic_ISBN :
1530-0889
Type :
conf
DOI :
10.1109/DSN.2011.5958225
Filename :
5958225
Link To Document :
بازگشت