Opening book details…
Can I read A Unit-based Symbolic Execution Method for Detecting Memory Corruption Vulnerabilities in Executable Codes on EtoBox?
A Unit-based Symbolic Execution Method for Detecting Memory Corruption Vulnerabilities in Executable Codes by Baradaran, Sara; Heidari, Mahdi; Kamali, Ali; Mouzarani, Maryam is a scholarly article available to read on EtoBox.
What is A Unit-based Symbolic Execution Method for Detecting Memory Corruption Vulnerabilities in Executable Codes about?
Memory corruption is a serious class of software vulnerabilities, which requires careful attention to be detected and removed from applications before getting exploited and harming the system users. Symbolic execution is a well-known method for analyzing programs and detecting various vulnerabilities, e.g., memory corruption. Although this method is sound and complete in theory, it faces some challenges, such as path explosion, when applied to real-world complex programs. In this paper, we present a method for improving the efficiency of symbolic execution and detecting four classes of memory corruption vulnerabilities in executable codes, i.e., heap-based buffer overflow, stack-based buffer overflow, use-after-free, and double-free. We perform symbolic execution only on test units rather than the whole program to avoid path explosion. In our method, test units are considered parts of the program's code, which might contain vulnerable statements and are statically identified based on the specifications of memory corruption vulnerabilities. Then, each test unit is symbolically executed to calculate path and vulnerability constraints of each statement of the unit, which determine the
- Author
- Baradaran, Sara; Heidari, Mahdi; Kamali, Ali; Mouzarani, Maryam
- Published
- 2022
- Language
- EN