Article ID: | iaor20121320 |
Volume: | 63 |
Issue: | 2 |
Start Page Number: | 469 |
End Page Number: | 480 |
Publication Date: | Jan 2012 |
Journal: | Computers and Mathematics with Applications |
Authors: | Zhang Ruoyu, Huang Shiqiu, Qi Zhengwei, Guan Haibing |
Keywords: | computers: information, networks |
The evolution of computer science has exposed us to the growing gravity of security problems and threats. Dynamic taint analysis is a prevalent approach to protect a program from malicious behaviors, but fails to provide any information about the code which is not executed. This paper describes a novel approach to overcome the limitation of traditional dynamic taint analysis by integrating static analysis into the system and presents framework SDCF to detect software vulnerabilities with high code coverage. Our experiments show that SDCF is not only able to provide efficient runtime protection by introducing an overhead of 4.16× based on the taint tracing technique, but is also capable of discovering latent software vulnerabilities which have not been exploited, and achieve code coverage of more than 90%.