Academic Journal

Systematic bug finding and fault localization enhanced with input data tracking

Bibliographic Details
Title: Systematic bug finding and fault localization enhanced with input data tracking
Authors: DeMott, Jared D. jdemott@vdalabs.com, Enbody, Richard J. enbody@cse.msu.edu, Punch, William F. punch@cse.msu.edu
Source: Computers & Security. Feb2013, Vol. 32, p130-157. 28p.
Subject Terms: *Information storage & retrieval systems, Computer software testing, Computer debugging software, Error messages (Computer science), Binary number system, Computer software security, Coding theory
Abstract: Abstract: Fault localization (FL) is the process of debugging erroneous code and directing analysts to the root cause of the bug. With this in mind, we have developed a distributed, end-to-end fuzzing and analysis system that starts with a binary, identifies bugs, and subsequently localizes the bug''s root cause. Our system does not require the test subject''s source code, nor do we require a test suite. Our work focuses on an important class of bugs, memory corruption errors, which usually have software security implications. Thus, our approach appeals to software attack researchers as well. In addition to our bug hunting and analysis framework, we have enhanced code-coverage based fault localization by incorporating input data tainting and tracking using a light-weight binary instrumentation technique. By capturing code coverage and select input data usage, our new FL algorithm is able to better localize faults, and therefore better assist analysts. We report the application of our approach on large, real-world applications (Firefox and VLC), as well as the classic Siemens benchmark and other test programs. [Copyright &y& Elsevier]
Copyright of Computers & Security is the property of Pergamon Press - An Imprint of Elsevier Science and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Business Source Index
FullText Links:
  – Type: other
Text:
  Availability: 0
CustomLinks:
  – Url: https://www.doi.org/10.1016/j.cose.2012.09.015?
    Name: ScienceDirect (all content) (s7799221)
    Category: fullText
    Text: View record from ScienceDirect
    MouseOverText: View record from ScienceDirect
Header DbId: bsx
DbLabel: Business Source Index
An: 85279296
RelevancyScore: 1171
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 1171.3779296875
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Systematic bug finding and fault localization enhanced with input data tracking
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22DeMott%2C+Jared+D%2E%22">DeMott, Jared D.</searchLink><i> jdemott@vdalabs.com</i><br /><searchLink fieldCode="AR" term="%22Enbody%2C+Richard+J%2E%22">Enbody, Richard J.</searchLink><i> enbody@cse.msu.edu</i><br /><searchLink fieldCode="AR" term="%22Punch%2C+William+F%2E%22">Punch, William F.</searchLink><i> punch@cse.msu.edu</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Computers+%26+Security%22">Computers & Security</searchLink>. Feb2013, Vol. 32, p130-157. 28p.
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: *<searchLink fieldCode="DE" term="%22Information+storage+%26+retrieval+systems%22">Information storage & retrieval systems</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+software+testing%22">Computer software testing</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+debugging+software%22">Computer debugging software</searchLink><br /><searchLink fieldCode="DE" term="%22Error+messages+%28Computer+science%29%22">Error messages (Computer science)</searchLink><br /><searchLink fieldCode="DE" term="%22Binary+number+system%22">Binary number system</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+software+security%22">Computer software security</searchLink><br /><searchLink fieldCode="DE" term="%22Coding+theory%22">Coding theory</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Abstract: Fault localization (FL) is the process of debugging erroneous code and directing analysts to the root cause of the bug. With this in mind, we have developed a distributed, end-to-end fuzzing and analysis system that starts with a binary, identifies bugs, and subsequently localizes the bug''s root cause. Our system does not require the test subject''s source code, nor do we require a test suite. Our work focuses on an important class of bugs, memory corruption errors, which usually have software security implications. Thus, our approach appeals to software attack researchers as well. In addition to our bug hunting and analysis framework, we have enhanced code-coverage based fault localization by incorporating input data tainting and tracking using a light-weight binary instrumentation technique. By capturing code coverage and select input data usage, our new FL algorithm is able to better localize faults, and therefore better assist analysts. We report the application of our approach on large, real-world applications (Firefox and VLC), as well as the classic Siemens benchmark and other test programs. [Copyright &y& Elsevier]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Computers & Security is the property of Pergamon Press - An Imprint of Elsevier Science and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=bsx&AN=85279296
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1016/j.cose.2012.09.015
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 28
        StartPage: 130
    Subjects:
      – SubjectFull: Information storage & retrieval systems
        Type: general
      – SubjectFull: Computer software testing
        Type: general
      – SubjectFull: Computer debugging software
        Type: general
      – SubjectFull: Error messages (Computer science)
        Type: general
      – SubjectFull: Binary number system
        Type: general
      – SubjectFull: Computer software security
        Type: general
      – SubjectFull: Coding theory
        Type: general
    Titles:
      – TitleFull: Systematic bug finding and fault localization enhanced with input data tracking
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: DeMott, Jared D.
      – PersonEntity:
          Name:
            NameFull: Enbody, Richard J.
      – PersonEntity:
          Name:
            NameFull: Punch, William F.
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 02
              Text: Feb2013
              Type: published
              Y: 2013
          Identifiers:
            – Type: issn-print
              Value: 01674048
          Numbering:
            – Type: volume
              Value: 32
          Titles:
            – TitleFull: Computers & Security
              Type: main
ResultId 1