arrow
Return

Automatically Patching Vulnerabilities of Binary Programs via Code Transfer From Correct Versions

delete2019-01-01
delete9
delete
OA
AI
胡易坤 (Yikun Hu)
Y
Yuanyuan Zhang
谷大武 (Dawu Gu) *
DOI:10.1109/ACCESS.2019.2901951delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
The security of binary programs is significantly threatened by software vulnerabilities. When vulnerabilities are found, those applications are exposed to malicious attacks that exploit the known vulnerabilities. Thus, it is necessary to patch them when vulnerabilities are reported to the public as soon as possible. However, it still heavily relies on manual work to locate and correct the corresponding defective code in the binary programs. In order to raise productivity and ensure software security, it becomes imperative to automate the process. In this paper, we propose BINPATCH to automatically patch known vulnerabilities of binary programs. It first locates the defective function, which contains the vulnerability, via similar code comparison. Then, it reuses the corresponding code from the correct version of the defective function as the patch code and inserts it to the defective function via binary rewriting. BINPATCH is evaluated on eight real-world vulnerabilities, and the experimental results show that it is able to not only locate the defective code effectively but also patch the code correctly.
Keywords:
Reverse engineering
binary code patching
binary program analysis
software security
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

S
shanghai jiao tong university
Scholars:
15.6W
Papers: 11.6W
Citations: 159