Source Code Patterns of Buffer Overflow Vulnerabilities in Firefox
dc.contributor.author | Schuckert, Felix | |
dc.contributor.author | Hildner, Max | |
dc.contributor.author | Katt, Basel | |
dc.contributor.author | Langweg, Hanno | |
dc.contributor.editor | Langweg, Hanno | |
dc.contributor.editor | Meier, Michael | |
dc.contributor.editor | Witt, Bernhard C. | |
dc.contributor.editor | Reinhardt, Delphine | |
dc.date.accessioned | 2018-03-22T12:40:43Z | |
dc.date.available | 2018-03-22T12:40:43Z | |
dc.date.issued | 2018 | |
dc.description.abstract | We investigated 50 randomly selected buffer overflow vulnerabilities in Firefox. The source code of these vulnerabilities and the corresponding patches were manually reviewed and patterns were identified. Our main contribution are taxonomies of errors, sinks and fixes seen from a developer's point of view. The results are compared to the CWE taxonomy with an emphasis on vulnerability details. Additionally, some ideas are presented on how the taxonomy could be used to improve the software security education. | en |
dc.identifier.doi | 10.18420/sicherheit2018_08 | |
dc.identifier.isbn | 978-3-88579-675-6 | |
dc.identifier.pissn | 1617-5468 | |
dc.identifier.uri | https://dl.gi.de/handle/20.500.12116/16298 | |
dc.language.iso | en | |
dc.publisher | Gesellschaft für Informatik e.V. | |
dc.relation.ispartof | SICHERHEIT 2018 | |
dc.relation.ispartofseries | Lecture Notes in Informatics (LNI) - Proceedings, Volume P-281 | |
dc.subject | Buffer Overflow | |
dc.subject | Source Code Patterns | |
dc.subject | Vulnerabilities | |
dc.subject | Code Analysis | |
dc.title | Source Code Patterns of Buffer Overflow Vulnerabilities in Firefox | en |
dc.type | Text/Conference Paper | |
gi.citation.endPage | 118 | |
gi.citation.publisherPlace | Bonn | |
gi.citation.startPage | 107 | |
gi.conference.date | 25.-27. April 2018 | |
gi.conference.location | Konstanz, Germany | |
gi.conference.sessiontitle | Wissenschaftliche Beiträge |
Dateien
Originalbündel
1 - 1 von 1