conference-paper

SecVerifier: A Practical Memory-Security Verifier

  • 2021 IEEE 21st International Conference on Software Quality, Reliability and Security Companion (QRS-C)
Research footprint

At a glance

Citations
0
References
4
Comments
0
Paper overview

Öz

Memory-related security vulnerabilities such as buffer overflow may cause severe consequences once exploited. Various technologies have been applied to discover them before a product is released, but they have significant false positives and false negatives. Formal verification has the reputation of mathematically reasoning about software properties, but it has limited scalability and is challenging to use. We have developed the novel manageable verification unit strategy to address the scalability issue and built a web-based verification service to lower the usage obstacles. With the system, we have verified 140K+ lines of real-world products and discovered 106 memory-related vulnerabilities that other technologies have missed.

Record transparency

Publication details

DOI
10.1109/qrs-c55045.2021.00133
OpenAlex
W4226247670
Document type
conference-paper
Language
EN
Source
2021 IEEE 21st International Conference on Software Quality, Reliability and Security Companion (QRS-C)
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.