Statically Detecting Likely Buffer Overflow Vulnerabilities

From: aleph1@securityfocus.com
Date: 09/16/01


Date: Sat, 15 Sep 2001 16:41:18 -0600
From: aleph1@securityfocus.com
To: secpapers@securityfocus.com
Subject: Statically Detecting Likely Buffer Overflow Vulnerabilities
Message-ID: <20010915164118.Z1818@securityfocus.com>

Statically Detecting Likely Buffer Overflow Vulnerabilities
David Larochelle and David Evans.

Buffer overflow attacks may be today's single most important security
threat. This paper presents a new approach to mitigating buffer overflow
vulnerabilities by detecting likely vulnerabilities through an analysis of
the program source code. Our approach exploits information provided in
semantic comments and uses lightweight and efficient static analyses. This
paper describes an implementation of our approach that extends the LCLint
annotation-assisted static checking tool. Our tool is as fast as a compiler
and nearly as easy to use. We present experience using our approach to
detect buffer overflow vulnerabilities in two security-sensitive programs.

http://www.cs.virginia.edu/~evans/usenix01-abstract.html
http://lclint.cs.virginia.edu/usenix01.pdf
http://lclint.cs.virginia.edu/usenix01.html

-- 
Elias Levy
SecurityFocus
http://www.securityfocus.com/
Si vis pacem, para bellum



Relevant Pages

  • [NT] IBM Lotus Notes Attachment Viewer Buffer Overflow Vulnerabilities
    ... IBM Lotus Notes Attachment Viewer Buffer Overflow Vulnerabilities ...
    (Securiteam)
  • Re: [Lit.] Buffer overruns
    ... note that the buffer overflow exploits that i quoted from the cve ... an attacker could succesfully attack a system using a buffer overflow ... one might conclude that if specialized hardware was being introduced ... buffer overflow vulnerabilities themselves are relatively prevalent). ...
    (sci.crypt)
  • Re: [Lit.] Buffer overruns
    ... note that the buffer overflow exploits that i quoted from the cve ... an attacker could succesfully attack a system using a buffer overflow ... one might conclude that if specialized hardware was being introduced ... buffer overflow vulnerabilities themselves are relatively prevalent). ...
    (comp.security.unix)
  • Re: [Lit.] Buffer overruns
    ... security conscience programming practices. ... yet buffer overflow vulnerabilities have persisted. ... perhaps it's about time for general programming practices to catch ...
    (sci.crypt)

Quantcast