Show simple item record

dc.contributor.authorPerkins, Jeff
dc.contributor.authorEikenberry, Jordan
dc.contributor.authorCoglio, Alessandro
dc.contributor.authorRinard, Martin
dc.date.accessioned2019-11-19T19:24:11Z
dc.date.available2019-11-19T19:24:11Z
dc.date.issued2019-11-19
dc.identifier.urihttps://hdl.handle.net/1721.1/122969
dc.description.abstractWe present ClearTrack, a system that tracks 32 bits of metadata for each primitive value in Java programs to detect and nullify a range of vulnerabilities such as integer overflow and underflow vulnerabilities, SQL injection vulnerabilities, and command injection vulnerabilities. Contributions include new techniques for eliminating false positives associated with benign integer overflows and underflows, new metadata-aware techniques for detecting and nullifying SQL and command injection attacks, and results from an evaluation of ClearTrack performed by a Test and Evaluation team hired by the sponsor of this research (an anonymous agency of the United States government). These results show that 1) ClearTrack operates successfully on Java programs comprising hundreds of thousands of lines of code (including instrumented jar files and Java system libraries, the majority of the applications comprise over 3 million lines of code), 2) because of computations such as cryptography and hash table calculations, these applications perform millions of benign integer overflows and underflows, and 3) ClearTrack successfully detects and nullifies all tested integer overflow and underflow, SQL injection, and command injection vulnerabilities in the benchmark applications.en_US
dc.language.isoen_USen_US
dc.rightsAttribution-NonCommercial-NoDerivs 3.0 United States*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/3.0/us/*
dc.subjectsecurityen_US
dc.subjectruntime instrumentationen_US
dc.subjectnumeric errrorsen_US
dc.titleComprehensive Java Metadata Tracking for Attack Detection and Repairen_US
dc.typeArticleen_US


Files in this item

Thumbnail
Thumbnail

This item appears in the following Collection(s)

Show simple item record