kirancodes.me
To Proof Maintenance & Beyond!
ICSE 2018★ Award

Spatio-temporal context reduction: a pointer-analysis-based static approach for detecting use-after-free vulnerabilities

Hua Yan, Yulei Sui, Shiping Chen, Jingling Xue

Abstract

Zero-day Use-After-Free (UAF) vulnerabilities are increasingly popular and highly dangerous, but few mitigations exist. We introduce a new pointer-analysis-based static analysis, CRed, for finding UAF bugs in multi-MLOC C source code efficiently and effectively. CRed achieves this by making three advances: (i) a spatio-temporal context reduction technique for scaling down soundly and precisely the exponential number of contexts that would otherwise be considered at a pair of free and use sites, (ii) a multi-stage analysis for filtering out false alarms efficiently, and (iii) a path-sensitive demand-driven approach for finding the points-to information required.

BibTeX
@inproceedings{Yan-al:ICSE18,
  author    = {Hua Yan and
               Yulei Sui and
               Shiping Chen and
               Jingling Xue},
  title     = {Spatio-temporal context reduction: a pointer-analysis-based static approach for detecting use-after-free vulnerabilities},
  booktitle = {ICSE},
  pages     = {327--337},
  publisher = {{ACM}},
  year      = {2018},
}

Related papers