,From proof-of-concept to exploitable

来源 :网络空间安全科学与技术(英文版) | 被引量 : 0次 | 上传用户:wufj77
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Exploitability assessment of vulnerabilities is important for both defenders and attackers.The ultimate way to assess the exploitability is crafting a working exploit.However,it usually takes tremendous hours and significant manual efforts.To address this issue,automated techniques can be adopted.Existing solutions usually explore in depth the crashing paths,i.e.,paths taken by proof-of-concept (PoC)inputs triggering vulnerabilities,and assess exploitability by finding exploitable states along the paths.However,exploitable states do not always exist in crashing paths.Moreover,existing solutions heavily rely on symbolic execution and are not scalable in path exploration and exploit generation.In this paper,we propose a novel solution to generate exploit for userspace programs or facilitate the process of crafting a keel UAF exploit.Technically,we utilize oriented fuzzing to explore diverging paths from vulnerability point.For userspace programs,we adopt a control-flow stitching solution to stitch crashing paths and diverging paths together to generate exploit.For keel UAF,we leverage a lightweight symbolic execution to identify,analyze and evaluate the system calls valuable and useful for exploiting vulnerabilities.We have developed a prototype system and evaluated it on a set of 19 CTF (capture the flag) programs and 15 realworld Linux keel UAF vulnerabilities.Experiment results showed it could generate exploit for most of the userspace test set,and it could also facilitate security mitigation bypassing and exploitability evaluation for keel test set.
其他文献
在分析课程教学设计内涵的基础上,阐述了课程教学设计的特点,分析了MindManager这种思维工具的功能与优势,以大学物理课程教学设计为例,展示了运用MindManagnr开展课程教学设
进入信息社会,在经济一体化与专业分工日益精细的情况下,合作意识与合作能力已经成为人们生存发展的重要品质.对于学生的学习活动也如此,学习过程中的交流可以使学生把实物的
法律是影响战争进程的重要因素之一,为有效应对未来海上作战中遇到的法律挑战,通过分析海战法规则的约束性、滞后性以及复杂电磁环境、周边海洋争端等诸多因素对未来海上作战
请下载后查看,本文暂不支持在线获取查看简介。 Please download to view, this article does not support online access to view profile.
环境是指周围的情况和条件,即眼睛看得到的和耳朵听得到的东西。在国内学英语不像在国外那样容易,因为我们所处的环境没有随处可见或循环出现的英语环境,为了有利于学生的英
2005年的股权分置改革对于迅速成长和发展的中国资本市场而言意义重大。围绕股权分置和股权分置改革的话题成为从业界到学界,从政府到民间最热门,也是最富有魅力的话题。  股
Astroturfing is a phenomenon in which sponsors of fake messages or reviews are masked because their intentions are not genuine.Astroturfing reviews are intentio
2006年伴随着我国股市的复苏繁荣,我国基金业迎来了第一个黄金发展期。截止到2006年12月31日,我国共有271只开放式基金,其中股票型基金100只,配置型(混合型)基金90只,债券型基金27只
讨论了“特色理论”课程如何在教学目标确立、课程特点分析、教学内容优化、教学方法创新、实践教学展开和考试方式改革等方面进行设计,提出了实现“以教材为依据、以问题为
作为2005年股权分置改革的产物和我国股票市场中少有的创新产品,权证一经推出就在市场中掀起了不小的波澜。权证出现的意义更多地被认为是在促进金融创新方面丰富了金融品种、