• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Buffer Access Monitoring for Enhanced Buffer Overflow Detection in Fuzzing
 
  • Details
  • Full
Options
October 21, 2024
Conference Paper
Title

Buffer Access Monitoring for Enhanced Buffer Overflow Detection in Fuzzing

Abstract
Buffer overflows remain one of the most critical and widespread vulnerabilities in software systems. Traditional fuzzing techniques often lack the precision required to reliably detect buffer overflows. This paper presents BufferMonitor, a novel approach to enhancing buffer overflow detection by integrating a comprehensive buffer monitoring system into fuzzing frameworks. Using the LLVM compiler framework, we instrument the system under test to collect detailed memory access information, including the distance of each access from buffer boundaries. By prioritizing inputs that generate minimal distances to these boundaries, our method significantly improves the likelihood of detecting potential overflows. This approach not only increases the possibility of identifying buffer overflows but can also identify them with greater accuracy than AddressSanitizer. This provides a robust solution for enhancing software security.
Author(s)
Barakat, Ramon  
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Josten, Silvan
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Schneider, Martin A.
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Mainwork
IEEE 32nd International Symposium on Modeling, Analysis and Simulation of Computer and Telecommunication Systems, MASCOTS 2024. Proceedings  
Conference
International Symposium on Modeling, Analysis and Simulation of Computer and Telecommunication Systems 2024  
DOI
10.1109/MASCOTS64422.2024.10786534
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Keyword(s)
  • Instruments

  • Buffer overflows

  • Fuzzing

  • Software systems

  • Telecommunications

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024