2018•Unpublished venueRequires access

Bintaint: A Static Taint Analysis Method for Binary Vulnerability Mining

Zenan Feng, Zhenyu Wang, Weiyu Dong, Rui Li Chang

Open publisher page 5 citations

Abstract

Vulnerabilities in the current network space has been increasingly concerned by all parties. More and more software is currently in the form of binary code in practical applications. Therefore, the research on vulnerability mining technology for binary code attracts more attention from the researchers. In order to address the problem of binary vulnerability mining, this paper focuses on the taint analysis, and proposes a method called Bintaint, which can perform static taint analysis and generate the taint control flow graph (TCFG). In addition, we implement a system based on Bintaint to reduce the path explosion in the traditional vulnerability analysis process. Combined with our bidirectional search technology and path guidance algorithm to assist the symbol execution technology to generate test cases, the high computational overhead caused by complex constraints can be reduced. Finally, we evaluate our method on X86 programs and six core programs in different architecture embedded devices, and the result shows that our method detect all known vulnerability without false negative and mitigates the problem of path explosion and computational overhead effectively.

About this research paper

What this paper is about

Vulnerabilities in the current network space has been increasingly concerned by all parties. More and more software is currently in the form of binary code in practical applications. Therefore, the research on vulnerability mining technology for binary code attracts more attention from the researchers. In order to address the problem of binary vulnerability mining, this paper focuses on the taint analysis, and proposes a method called Bintaint, which can perform static taint analysis and generate the taint control flow graph (TCFG). In addition, we implement a system based on Bintaint to reduce the path explosion in the traditional vulnerability analysis process. Combined with our bidirectional search technology and path guidance algorithm to assist the symbol execution technology to generate test cases, the high computational overhead caused by complex constraints can be reduced. Finally, we evaluate our method on X86 programs and six core programs in different architecture embedded devices, and the result shows that our method detect all known vulnerability without false negative and mitigates the problem of path explosion and computational overhead effectively.

Why it matters

OpenAlex reports 5 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Vulnerabilities in the current network space has been increasingly concerned by all parties. More and more software is currently in the form of binary code in practical applications. Therefore, the research on vulnerability mining technology for binary code attracts more attention from the researchers. In order to address the problem of binary vulnerability mining, this paper focuses on the taint analysis, and proposes a method called Bintaint, which can perform static taint analysis and generate the taint control flow graph (TCFG). In addition, we implement a system based on Bintaint to reduce the path explosion in the traditional vulnerability analysis process. Combined with our bidirectional search technology and path guidance algorithm to assist the symbol execution technology to generate test cases, the high computational overhead caused by complex constraints can be reduced. Finally, we evaluate our method on X86 programs and six core programs in different architecture embedded devices, and the result shows that our method detect all known vulnerability without false negative and mitigates the problem of path explosion and computational overhead effectively.

Key concepts: Computer science, Taint checking, Vulnerability (computing), Overhead (engineering), Static analysis, Path (computing), Vulnerability assessment, Software

Related papers

Back to paper searchBrowse research topicsOriginal source
Bintaint: A Static Taint Analysis Method for Binary Vulnerability Mining — Research Paper | ScholarLens