An Empirical Study on Detecting and Fixing Buffer Overflow Bugs

Tao Ye, Lingming Zhang, Linzhang Wang, Xuandong Li

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Buffer overflow is one of the most common types of software security vulnerabilities. Although researchers have proposed various static and dynamic techniques for buffer overflow detection, buffer overflow attacks against both legacy and newly-deployed software systems are still quite prevalent. Compared with dynamic detection techniques, static techniques are more systematic and scalable. However, there are few studies on the effectiveness of state-of-the-art static buffer overflow detection techniques. In this paper, we perform an in-depth quantitative and qualitative study on static buffer overflow detection. More specifically, we obtain both the buggy and fixed versions of 100 buffer overflow bugs from 63 real-world projects totalling 28 MLoC (Millions of Lines of Code) based on the reports in Common Vulnerabilities and Exposures (CVE). Then, quantitatively, we apply Fortify, Checkmarx, and Splint to all the buggy versions to investigate their false negatives, and also apply them to all the fixed versions to investigate their false positives. We also qualitatively investigate the causes for the false-negatives and false-positives of studied techniques to guide the design and implementation of more advanced buffer overflow detection techniques. Finally, we also categorized the patterns of manual buffer overflow repair actions to guide automated repair techniques for buffer overflow. The experiment data is available at http://bo-study.github.io/Buffer-Overflow-Cases/.

Original languageEnglish (US)
Title of host publicationProceedings - 2016 IEEE International Conference on Software Testing, Verification and Validation, ICST 2016
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages91-101
Number of pages11
ISBN (Electronic)9781509018260
DOIs
StatePublished - Jul 18 2016
Externally publishedYes
Event9th IEEE International Conference on Software Testing, Verification and Validation, ICST 2016 - Chicago, United States
Duration: Apr 10 2016Apr 15 2016

Publication series

NameProceedings - 2016 IEEE International Conference on Software Testing, Verification and Validation, ICST 2016

Other

Other9th IEEE International Conference on Software Testing, Verification and Validation, ICST 2016
Country/TerritoryUnited States
CityChicago
Period4/10/164/15/16

ASJC Scopus subject areas

  • Software
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'An Empirical Study on Detecting and Fixing Buffer Overflow Bugs'. Together they form a unique fingerprint.

Cite this