Static program analysis assisted dynamic taint tracking for software vulnerability discovery

Static program analysis assisted dynamic taint tracking for software vulnerability discovery

0.00 Avg rating0 Votes
Article ID: iaor20121320
Volume: 63
Issue: 2
Start Page Number: 469
End Page Number: 480
Publication Date: Jan 2012
Journal: Computers and Mathematics with Applications
Authors: , , ,
Keywords: computers: information, networks
Abstract:

The evolution of computer science has exposed us to the growing gravity of security problems and threats. Dynamic taint analysis is a prevalent approach to protect a program from malicious behaviors, but fails to provide any information about the code which is not executed. This paper describes a novel approach to overcome the limitation of traditional dynamic taint analysis by integrating static analysis into the system and presents framework SDCF to detect software vulnerabilities with high code coverage. Our experiments show that SDCF is not only able to provide efficient runtime protection by introducing an overhead of 4.16× based on the taint tracing technique, but is also capable of discovering latent software vulnerabilities which have not been exploited, and achieve code coverage of more than 90%.

Reviews

Required fields are marked *. Your email address will not be published.