Matches in SemOpenAlex for { <https://semopenalex.org/work/W4360764512> ?p ?o ?g. }
- W4360764512 abstract "Nowadays, attackers are increasingly using Use-After-Free(UAF) vulnerabilities to create threats against software security. Existing static approaches for UAF detection are capable of finding potential bugs in the large code base. In most cases, analysts perform manual inspections to verify whether the warnings detected by static analysis are real vulnerabilities. However, due to the complex constraints of constructing UAF vulnerability, it is very time and cost-intensive to screen all warnings. In fact, many warnings should be discarded before the manual inspection phase because they are almost impossible to get triggered in real-world, and it is often overlooked by current static analysis techniques. In this paper, we introduce a metric-based static analysis approach, named Mad, for efficiently identifying UAF vulner-abilities by removing redundant warnings. We design two sets of systematic metrics to drive Mad. First, we apply lightweight static analysis to locate potential UAF pairs and use Feature Metrics to gather their feature information into an evaluation pool. Then, we use Controllability Metrics to rank the evaluation pools and filter out the high ones as candidates for subsequent manual inspection. We have implemented Madand evaluated it using Juliet Test Suite and a set of eight open-source C programs. Madcan locate all UAF bugs in Juliet Test Suite within a recognizable range, showing effectiveness and scalability by detecting 5 known CVEs with 1,286 KLOC in just 1.6 hours. Furthermore, we can achieve an average 75% reduction rate for reported warnings and save about half the time in locating UAF vulnerabilities during manual inspection." @default.
- W4360764512 created "2023-03-25" @default.
- W4360764512 creator A5010430600 @default.
- W4360764512 creator A5013217019 @default.
- W4360764512 creator A5018957416 @default.
- W4360764512 creator A5049991780 @default.
- W4360764512 creator A5052985508 @default.
- W4360764512 creator A5055214896 @default.
- W4360764512 date "2022-12-01" @default.
- W4360764512 modified "2023-10-16" @default.
- W4360764512 title "An Efficient Metric-Based Approach for Static Use-After-Free Detection" @default.
- W4360764512 cites W1563577331 @default.
- W4360764512 cites W1984471991 @default.
- W4360764512 cites W1992114977 @default.
- W4360764512 cites W1996567876 @default.
- W4360764512 cites W1997394198 @default.
- W4360764512 cites W2008106620 @default.
- W4360764512 cites W2059278087 @default.
- W4360764512 cites W2094619820 @default.
- W4360764512 cites W2117798902 @default.
- W4360764512 cites W2146649139 @default.
- W4360764512 cites W2547862110 @default.
- W4360764512 cites W2773223713 @default.
- W4360764512 cites W2794889478 @default.
- W4360764512 cites W3019415692 @default.
- W4360764512 cites W3092430836 @default.
- W4360764512 cites W4240399292 @default.
- W4360764512 doi "https://doi.org/10.1109/ispa-bdcloud-socialcom-sustaincom57177.2022.00015" @default.
- W4360764512 hasPublicationYear "2022" @default.
- W4360764512 type Work @default.
- W4360764512 citedByCount "0" @default.
- W4360764512 crossrefType "proceedings-article" @default.
- W4360764512 hasAuthorship W4360764512A5010430600 @default.
- W4360764512 hasAuthorship W4360764512A5013217019 @default.
- W4360764512 hasAuthorship W4360764512A5018957416 @default.
- W4360764512 hasAuthorship W4360764512A5049991780 @default.
- W4360764512 hasAuthorship W4360764512A5052985508 @default.
- W4360764512 hasAuthorship W4360764512A5055214896 @default.
- W4360764512 hasConcept C114614502 @default.
- W4360764512 hasConcept C119857082 @default.
- W4360764512 hasConcept C124101348 @default.
- W4360764512 hasConcept C127413603 @default.
- W4360764512 hasConcept C128942645 @default.
- W4360764512 hasConcept C151552104 @default.
- W4360764512 hasConcept C152877465 @default.
- W4360764512 hasConcept C164226766 @default.
- W4360764512 hasConcept C166957645 @default.
- W4360764512 hasConcept C176217482 @default.
- W4360764512 hasConcept C177264268 @default.
- W4360764512 hasConcept C199360897 @default.
- W4360764512 hasConcept C21547014 @default.
- W4360764512 hasConcept C2776760102 @default.
- W4360764512 hasConcept C2777904410 @default.
- W4360764512 hasConcept C28826006 @default.
- W4360764512 hasConcept C33923547 @default.
- W4360764512 hasConcept C38652104 @default.
- W4360764512 hasConcept C41008148 @default.
- W4360764512 hasConcept C43126263 @default.
- W4360764512 hasConcept C48044578 @default.
- W4360764512 hasConcept C48209547 @default.
- W4360764512 hasConcept C77088390 @default.
- W4360764512 hasConcept C79581498 @default.
- W4360764512 hasConcept C95457728 @default.
- W4360764512 hasConcept C95713431 @default.
- W4360764512 hasConcept C97686452 @default.
- W4360764512 hasConceptScore W4360764512C114614502 @default.
- W4360764512 hasConceptScore W4360764512C119857082 @default.
- W4360764512 hasConceptScore W4360764512C124101348 @default.
- W4360764512 hasConceptScore W4360764512C127413603 @default.
- W4360764512 hasConceptScore W4360764512C128942645 @default.
- W4360764512 hasConceptScore W4360764512C151552104 @default.
- W4360764512 hasConceptScore W4360764512C152877465 @default.
- W4360764512 hasConceptScore W4360764512C164226766 @default.
- W4360764512 hasConceptScore W4360764512C166957645 @default.
- W4360764512 hasConceptScore W4360764512C176217482 @default.
- W4360764512 hasConceptScore W4360764512C177264268 @default.
- W4360764512 hasConceptScore W4360764512C199360897 @default.
- W4360764512 hasConceptScore W4360764512C21547014 @default.
- W4360764512 hasConceptScore W4360764512C2776760102 @default.
- W4360764512 hasConceptScore W4360764512C2777904410 @default.
- W4360764512 hasConceptScore W4360764512C28826006 @default.
- W4360764512 hasConceptScore W4360764512C33923547 @default.
- W4360764512 hasConceptScore W4360764512C38652104 @default.
- W4360764512 hasConceptScore W4360764512C41008148 @default.
- W4360764512 hasConceptScore W4360764512C43126263 @default.
- W4360764512 hasConceptScore W4360764512C48044578 @default.
- W4360764512 hasConceptScore W4360764512C48209547 @default.
- W4360764512 hasConceptScore W4360764512C77088390 @default.
- W4360764512 hasConceptScore W4360764512C79581498 @default.
- W4360764512 hasConceptScore W4360764512C95457728 @default.
- W4360764512 hasConceptScore W4360764512C95713431 @default.
- W4360764512 hasConceptScore W4360764512C97686452 @default.
- W4360764512 hasFunder F4320321001 @default.
- W4360764512 hasFunder F4320322847 @default.
- W4360764512 hasLocation W43607645121 @default.
- W4360764512 hasOpenAccess W4360764512 @default.
- W4360764512 hasPrimaryLocation W43607645121 @default.
- W4360764512 hasRelatedWork W2465616004 @default.
- W4360764512 hasRelatedWork W2737894786 @default.
- W4360764512 hasRelatedWork W2806773351 @default.