Generating vulnerability signatures for string manipulating programs using automata-based forward and backward symbolic analyses

29Citations
Citations of this article
27Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Given a program and an attack pattern (specified as a regular expression), we automatically generate string-based vulnerability signatures, i.e., a characterization that includes all malicious inputs that can be used to generate attacks. We use an automata-based string analysis framework. Using forward reachability analysis we compute an over-approximation of all possible values that string variables can take at each program point. Intersecting these with the attack pattern yields the potential attack strings if the program is vulnerable. Using backward analysis we compute an over-approximation of all possible inputs that can generate those attack strings. In addition to identifying existing vulnerabilities and their causes, these vulnerability signatures can be used to filter out malicious inputs. Our approach extends the prior work on automata-based string analysis by providing a backward symbolic analysis that includes a symbolic pre-image computation for deterministic finite automata on common string manipulating functions such as concatenation and replacement. © 2009 IEEE.

Cite

CITATION STYLE

APA

Yu, F., Alkhalaf, M., & Bultan, T. (2009). Generating vulnerability signatures for string manipulating programs using automata-based forward and backward symbolic analyses. In ASE2009 - 24th IEEE/ACM International Conference on Automated Software Engineering (pp. 605–609). https://doi.org/10.1109/ASE.2009.20

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free