Towards Practical Reactive Security Audit Using Extended Static Checkers

J. Vanegue, S. K. Lahiri
2013 2013 IEEE Symposium on Security and Privacy  
This paper describes our experience of performing reactive security audit of known security vulnerabilities in core operating system and browser COM components, using an extended static checker HAVOC-LITE. We describe the extensions made to the tool to be applicable on such large C++ components, along with our experience of using an extended static checker in the large. We argue that the use of such checkers as a configurable static analysis in the hands of security auditors can be an effective
more » ... tool for finding variations of known vulnerabilities. The effort has led to finding and fixing around 70 previously unknown security vulnerabilities in over 10 millions lines operating system and browser code.
doi:10.1109/sp.2013.12 dblp:conf/sp/VanegueL13 fatcat:arpaam45kjhufgj3va4imypwhi