Using type qualifiers to analyze untrusted integers and detecting security flaws in C programs

16Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Incomplete or improper input validation is one of the major sources of security bugs in programs. While traditional approaches often focus on detecting string related buffer overflow vulnerabilities, we present an approach to automatically detect potential integer misuse, such as integer overflows in C programs. Our tool is based on CQual, a static analysis tool using type theory. Our techniques have been implemented and tested on several widely used open source applications. Using the tool, we found known and unknown integer related vulnerabilities in these applications. © Springer-Verlag Berlin Heidelberg 2006.

Cite

CITATION STYLE

APA

Ceesay, E. N., Zhou, J., Gertz, M., Levitt, K., & Bishop, M. (2006). Using type qualifiers to analyze untrusted integers and detecting security flaws in C programs. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 4064 LNCS, pp. 1–16). Springer Verlag. https://doi.org/10.1007/11790754_1

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free