Enhancement of Accuracy of Exploitability Analysis Tools for Crashes
Jeon, Hyeon-gu; Eom, Ki-Jin; Mok, Seong-Kyun; Cho, Eun-Sun;
To enhance the reliability of programs, developers use fuzzing tools in test processes to identify vulnerabilities so that they can be fixed ahead of time. In this case, the developers consider the security-related vulnerabilities to be the most critical ones that should be urgently fixed to avoid possible exploitation by attackers. However, developers without much experience of analysis of vulnerabilities usually rely on tools to pick out the security-related crashes from the normal crashes. In this paper, we suggest a static analysis-based tool to help developers to make their programs more reliable by identifying security-related crashes among them. This paper includes experimental results, and compares them to the results from MSEC !exploitable for the same sets of crashes.
static analysis;crash;exploitability;taint analysis;
