메뉴 건너뛰기




Volumn , Issue , 2009, Pages 208-215

BRICK: A binary tool for run-time detecting and locating integer-based vulnerability

Author keywords

[No Author keywords available]

Indexed keywords

DYNAMIC BINARY INSTRUMENTATION; FALSE POSITIVE; PLUG-INS; REAL SOFTWARES; RECOMPILATION; ROOT CAUSE; RUNTIMES; SOFTWARE SECURITY; SOURCE CODE ANALYSIS; SOURCE CODES; TYPE INFERENCES;

EID: 70349857932     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1109/ARES.2009.77     Document Type: Conference Paper
Times cited : (38)

References (41)
  • 1
    • 35448955692 scopus 로고    scopus 로고
    • Valgrind: A framework for heavy weight dynamic binary instrumentation
    • San Diego, California, USA, June
    • N.Nethercote and J. Seward. Valgrind: A framework for heavy weight dynamic binary instrumentation. In Proceedings of PLDI 2007, San Diego, California, USA, June 2007.
    • (2007) Proceedings of PLDI
    • Nethercote, N.1    Seward, J.2
  • 2
    • 70349886980 scopus 로고    scopus 로고
    • D. A. Molnar and D. Wagner. Catchconv: Symbolic execution and run-time type inference for integer conversion errors. Technical Report UCB/EECS-2007-23, EECS Department, University of California, Berkeley, February 2007.
    • D. A. Molnar and D. Wagner. Catchconv: Symbolic execution and run-time type inference for integer conversion errors. Technical Report UCB/EECS-2007-23, EECS Department, University of California, Berkeley, February 2007.
  • 4
    • 70349863791 scopus 로고    scopus 로고
    • May,2007, Online, Available
    • CVE: Vulnerability Type Distributions. May,2007. [Online]. Available: http://cve.mitre.org/docs/vuln-trends/vuln-trends.pdf.
    • Vulnerability Type Distributions
  • 5
    • 70349863790 scopus 로고    scopus 로고
    • VLC Media Player Integer signedness error vulnerability, CVE, 2008. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2008-3794.
    • "VLC Media Player Integer signedness error vulnerability," CVE, 2008. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2008-3794.
  • 6
    • 70349851404 scopus 로고    scopus 로고
    • VLC Media Player Integer overflow vulnerability, CVE, 2008.[Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE- 2008-3732.
    • "VLC Media Player Integer overflow vulnerability," CVE, 2008.[Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE- 2008-3732.
  • 7
    • 70349856590 scopus 로고    scopus 로고
    • Linux Kernel Integer underflow vulnerability, CVE, 2007. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007- 4997.
    • "Linux Kernel Integer underflow vulnerability," CVE, 2007. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007- 4997.
  • 8
    • 70349851407 scopus 로고    scopus 로고
    • SSH CRC-32 compensation attack detector vulnerability, CVE, Feb 2001. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi? name=CVE-2001-0144.
    • "SSH CRC-32 compensation attack detector vulnerability," CVE, Feb 2001. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi? name=CVE-2001-0144.
  • 9
    • 70349863789 scopus 로고    scopus 로고
    • R. Wojtczuk. Uqbtng: a tool capable of automatically finding integer overflows in win32 binaries. In 22nd Chaos Communication Congress, 2005.
    • R. Wojtczuk. Uqbtng: a tool capable of automatically finding integer overflows in win32 binaries. In 22nd Chaos Communication Congress, 2005.
  • 11
    • 70349885896 scopus 로고    scopus 로고
    • Phrack Inc, Dec 2002, Online, Available
    • O. Horovitz. Big loop integer protection. Phrack Inc., Dec 2002. [Online]. Available: http://www.phrack.org/issues.html?issue=60&id= 9#article.
    • Big loop integer protection
    • Horovitz, O.1
  • 15
    • 70349877317 scopus 로고    scopus 로고
    • Ada95 Language Reference Manual, ISO/IEC, 1995.
    • Ada95 Language Reference Manual, ISO/IEC, 1995.
  • 18
    • 84870666315 scopus 로고    scopus 로고
    • GNU mailutils imap4d remote integer overflow vulnerability, Sep 2004, Online, Available
    • "GNU mailutils imap4d remote integer overflow vulnerability," SecurityFocus, Sep 2004. [Online]. Available: http://www.securityfocus.com/bid/ 11198/.
    • SecurityFocus
  • 19
    • 70349867141 scopus 로고    scopus 로고
    • Linux Kernel Integer underflow vulnerability, CVE, 2007. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007- 2875.
    • "Linux Kernel Integer underflow vulnerability," CVE, 2007. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007- 2875.
  • 20
    • 70349877312 scopus 로고    scopus 로고
    • Gocr ReadPGM NetPBM remote client-side integer overflow vulnerability, CVE, April 2005. [Online].Available: http://cve.mitre.org/ cgi-bin/cvename.cgi?name=CVE-2005-1141.
    • "Gocr ReadPGM NetPBM remote client-side integer overflow vulnerability," CVE, April 2005. [Online].Available: http://cve.mitre.org/ cgi-bin/cvename.cgi?name=CVE-2005-1141.
  • 22
    • 70349886976 scopus 로고    scopus 로고
    • Integer overflow in PHP 5.2.5 and prior, CVE, 2008. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1384.
    • "Integer overflow in PHP 5.2.5 and prior," CVE, 2008. [Online]. Available: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1384.
  • 23
    • 70349858718 scopus 로고    scopus 로고
    • Dec, 2006, Online, Available
    • Michael Howard. Integer Overflow and operator::new, Dec, 2006. [Online]. Available: http://blogs.msdn.com/michael-howard/archive/2005/12/06/500629.aspx.
    • Integer Overflow and operator::new
    • Howard, M.1
  • 24
    • 85011293817 scopus 로고    scopus 로고
    • David Evans, John Guttag, James Horning, and Yang Meng Tan. LCLint:A tool for using specification to check code. In Proceedings of the ACM SIGSOFT 94 Symposium on the Foundations of Software Engineering, pages 87-96,1994.
    • David Evans, John Guttag, James Horning, and Yang Meng Tan. LCLint:A tool for using specification to check code. In Proceedings of the ACM SIGSOFT 94 Symposium on the Foundations of Software Engineering, pages 87-96,1994.
  • 27
    • 33745798878 scopus 로고    scopus 로고
    • PaX Project
    • PaX Project. The PaX project, 2004. http://pax. grsecurity.net/.
    • (2004) The PaX project
  • 30
    • 85084160243 scopus 로고    scopus 로고
    • Stack-Guard:Automatic adaptive detection and prevention of buffer-overflow attacks
    • San Antonio, Texas,January
    • C. Cowan,C. Pu,D.Maier,J.Walpole et al. Stack-Guard:Automatic adaptive detection and prevention of buffer-overflow attacks. In Proceedings of the 7th USENIX Security Conference, San Antonio, Texas,January,1998.
    • (1998) Proceedings of the 7th USENIX Security Conference
    • Cowan, C.1    Pu, C.2    Maier, D.3    Walpole, J.4
  • 36
    • 33845919861 scopus 로고    scopus 로고
    • Z.Lin, B.Mao and L.Xie. LibsafeXP:A Pratical and Transparent Tool for Run-time Buffer Overflow Preventions. In Proc. Of the 7th Annual IEEE Information Assurance Workshop(IAW06).West Point, NY. USA, June, 2006.
    • Z.Lin, B.Mao and L.Xie. LibsafeXP:A Pratical and Transparent Tool for Run-time Buffer Overflow Preventions. In Proc. Of the 7th Annual IEEE Information Assurance Workshop(IAW06).West Point, NY. USA, June, 2006.
  • 38
    • 70349851400 scopus 로고    scopus 로고
    • CVE version: 20061101, CVE. [Online].Available: http://www.cve.mitre.org/ cgi-bin/cvekey.cgi?keyword=integer.
    • CVE version: 20061101, CVE. [Online].Available: http://www.cve.mitre.org/ cgi-bin/cvekey.cgi?keyword=integer.


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.