Trudy SPIIRAN
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Informatics and Automation:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Trudy SPIIRAN, 2015, Issue 42, Pages 212–231
DOI: https://doi.org/10.15622/sp.42.11
(Mi trspy835)
 

A Model, Algorithms and Software Tool for Vulnerabilities Detection in Machine Code

M. O. Shudrak, V. V. Zolotarev

Siberian State Aerospace University (SibSAU)
Abstract: In the article we consider the problem of vulnerabilities detection in machine code. In this paper, disadvantages of current solutions in case of possibility to detect vulnerabilities in view of threats to confidential information that is processed in vulnerable software are highlighted. To solve this problem, we propose original model of vulnerabilities detection in program trace, its algorithmic support and software implementation. The model provides formal criteria to distinct bug from vulnerability taking into account distribution of protected information in the memory of software under test. We use tainted data analysis technique to highlight such memory regions. In addition, we conduct experimental evaluation of developed system efficiency which demonstrates that our solution allows detecting 5 types of Windows software vulnerabilities more and 4 types Linux software vulnerabilities more than existing analogs.
Keywords: vulnerability; machine code; dynamic analysis; bug; criteria.
Document Type: Article
UDC: 004.056
Language: Russian


Citation: M. O. Shudrak, V. V. Zolotarev, “A Model, Algorithms and Software Tool for Vulnerabilities Detection in Machine Code”, Tr. SPIIRAN, 42 (2015), 212–231
Linking options:
  • https://www.mathnet.ru/eng/trspy835
  • https://www.mathnet.ru/eng/trspy/v42/p212
  • Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Informatics and Automation
    Statistics & downloads:
    Abstract page:171
    Full-text PDF :92
    First page:2
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024