DISCOVER: detecting algorithmic complexity vulnerabilities
Abstract
Algorithmic Complexity Vulnerabilities (ACV) are a class of vulnerabilities that enable Denial of Service Attacks. ACVs stem from asymmetric consumption of resources due to complex loop termination logic, recursion, and/or resource intensive library APIs. Completely automated detection of ACVs is intractable and it calls for tools that assist human analysts.
BibTeX
@inproceedings{Awadhutkar-al:FSE19,
author = {Payas Awadhutkar and
Ganesh Ram Santhanam and
Benjamin Holland and
Suresh C. Kothari},
title = {{DISCOVER:} detecting algorithmic complexity vulnerabilities},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {1129--1133},
publisher = {{ACM}},
year = {2019},
}