arrow
Return

Emulating representative software vulnerabilities using field data

delete2018-08-25
delete4
PRE
AI
R
Raul Barbosa *
F
Frederico Cerveira
L
Luís Gonçalo
H
Henrique Madeira
DOI:10.1007/s00607-018-0657-ydelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Security vulnerabilities are a concern in systems and software exposed via networked interfaces. Previous research has shown that only a minority of vulnerabilities can be emulated through software fault injection techniques. This paper aims to accurately emulate software security vulnerabilities. To this end, the paper provides a field-data study on the operators needed to emulate vulnerabilities in software written in the C programming language. A practical implementation is constructed and the feasibility of emulating software vulnerabilities is evaluated. The emulation operators were obtained by analyzing publicly available vulnerability databases for the Linux kernel, the Xen hypervisor, and the OpenSSH tool. The results show that a typical security vulnerability involves a single function and consists of combinations of up to three fault operator instances. The expected impact of this study is to allow practical emulation of security defects in large software projects, to support software quality and security assessment.
Keywords:
Security
Dependability
Security vulnerabilities
Software faults
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computing
IF:
2.8
Papers:
2.3K
Citations:
3.5K

Organization

U
universidade de coimbra
Scholars:
1.9W
Papers: 1.6W
Citations: 16