Loading [MathJax]/extensions/MathMenu.js
Automatic detection of integer sign vulnerabilities | IEEE Conference Publication | IEEE Xplore

Automatic detection of integer sign vulnerabilities


Abstract:

The integer sign vulnerability is a comparatively new and subtle type of vulnerabilities, they can compromise system security. Especially, if a sign vulnerability occurs ...Show More

Abstract:

The integer sign vulnerability is a comparatively new and subtle type of vulnerabilities, they can compromise system security. Especially, if a sign vulnerability occurs in operating system kernel, it may result in very serious invalid read/write operations to kernel memory area. Unfortunately, little attention has been paid to static detecting them automatically. This paper presents a novel approach to detecting sign vulnerabilities in Linux kernel using type qualifier technique. We introduce three pairs of type qualifier and corresponding lattices to identify some key kernel data and relationships between them. Based on an extended type inference tool, we are able to effectively detect known and unknown sign vulnerabilities from elaborately preprocessed Linux kernel files. Our experiences demonstrate that type qualifier technique can be applied to detect sign vulnerabilities effectively.
Date of Conference: 20-23 June 2008
Date Added to IEEE Xplore: 26 August 2008
ISBN Information:
Conference Location: Changsha

Contact IEEE to Subscribe

References

References is not available for this document.