arrow
返回

A Stack Memory Abstraction and Symbolic Analysis Framework for Executables

delete2016-04-27
delete2
PRE
AI
A
Aparna Kotha
R
Rajeev Barua
A
Angelos D. Keromytis
DOI:10.1145/2897511delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
This article makes three contributions regarding reverse-engineering of executables. First, techniques are presented for recovering a precise and correct stack-memory model in executables while addressing executable-specific challenges such as indirect control transfers. Next, the enhanced memory model is employed to define a novel symbolic analysis framework for executables that can perform the same types of program analyses as source-level tools. Third, a demand-driven framework is presented to enhance the scalability of the symbolic analysis framework. Existing symbolic analysis frameworks for executables fail to simultaneously maintain the properties of correct representation, a precise stack-memory model, and scalability. Furthermore, they ignore memory-allocated variables when defining symbolic analysis mechanisms. Our methods do not use symbolic, relocation or debug information, which are usually absent in deployed binaries. We describe our framework, highlighting the novel intellectual contributions of our approach and demonstrating its efficacy and robustness. Our techniques improve the precision of existing stack-memory models by 25%, enhance scalability of our basic symbolic analysis mechanism by 10x, and successfully uncovers five previously undiscovered information-flow vulnerabilities in several widely used programs.
Keyword:
Executable code
program analysis
information-flow security
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

A
ACM Transactions on Software Engineering and Methodology
IF:
6.2
论文数:
1.2K
被引数:
3.4K

机构

University System of Maryland 封面图
University System of Maryland
学者数:
6.4W
论文数: 5.6W
被引数: 113