{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T06:03:54Z","timestamp":1778220234080,"version":"3.51.4"},"reference-count":28,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2020,9,8]],"date-time":"2020-09-08T00:00:00Z","timestamp":1599523200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,9,8]],"date-time":"2020-09-08T00:00:00Z","timestamp":1599523200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2020,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The Integer-Overflow-to-Buffer-Overflow (IO2BO) vulnerability has been widely exploited by attackers to cause severe damages to computer systems. Automatically identifying this kind of vulnerability is critical for software security. Despite many works have been done to mitigate integer overflow, existing tools either report large number of false positives or introduce unacceptable time consumption. To address this problem, in this article we present a static analysis framework. It first constructs an inter-procedural call graph and utilizes taint analysis to accurately identify potential IO2BO vulnerabilities. Then it uses a light-weight method to further filter out false positives. Specifically, it generates constraints representing the conditions under which a potential IO2BO vulnerability can be triggered, and feeds the constraints to SMT solver to decide their satisfiability. We have implemented a prototype system ELAID based on LLVM, and evaluated it on 228 programs of the NIST\u2019s SAMATE Juliet test suite and 14 known IO2BO vulnerabilities in real world. The experiment results show that our system can effectively and efficiently detect all known IO2BO vulnerabilities.<\/jats:p>","DOI":"10.1186\/s42400-020-00058-2","type":"journal-article","created":{"date-parts":[[2020,9,8]],"date-time":"2020-09-08T00:02:47Z","timestamp":1599523367000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["ELAID: detecting integer-Overflow-to-Buffer-Overflow vulnerabilities by light-weight and accurate static analysis"],"prefix":"10.1186","volume":"3","author":[{"given":"Lili","family":"Xu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingjie","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Feng","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Huo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,9,8]]},"reference":[{"key":"58_CR1","volume-title":"Proceedings of the Network and Distributed System Security Symposium, NDSS 2007, 28th February - 2nd March 2007","author":"D Brumley","year":"2007","unstructured":"Brumley, D, Song DX, Chiueh T, Johnson R, Lin H (2007) RICH: automatically protecting against integer-based vulnerabilities In: Proceedings of the Network and Distributed System Security Symposium, NDSS 2007, 28th February - 2nd March 2007.. The Internet Society, San Diego."},{"key":"58_CR2","volume-title":"Efficient smt solving for bit-vectors and the extensional theory of arrays. PhD thesis","author":"R Brummayer","year":"2009","unstructured":"Brummayer, R (2009) Efficient smt solving for bit-vectors and the extensional theory of arrays. PhD thesis. Johannes Kepler University, Linz."},{"key":"58_CR3","first-page":"898","volume-title":"Chinese Journal of Computers, vol 35","author":"K Chen","year":"2012","unstructured":"Chen, K, Feng D, Su P (2012) Dynamic overflow vulnerability detection method based on finite csp(in chinese) In: Chinese Journal of Computers, vol 35, 898\u2013909.. Science Press, Beijing."},{"key":"58_CR4","first-page":"336","volume-title":"Information and Communications Security, 11th International Conference, ICICS 2009, December 14-17, 2009. Proceedings. LNCS, vol 5927","author":"P Chen","year":"2009","unstructured":"Chen, P, Han H, Wang Y, Shen X, Yin X, Mao B, Xie L (2009) Intfinder: Automatically detecting integer bugs in x86 binary program In: Information and Communications Security, 11th International Conference, ICICS 2009, December 14-17, 2009. Proceedings. LNCS, vol 5927, 336\u2013345.. Springer, Beijing."},{"key":"58_CR5","volume-title":"Proceedings of the 14th USENIX Security Symposium, Baltimore, MD, USA, July 31 - August 5, 2005","author":"S Chen","year":"2005","unstructured":"Chen, S, Xu J, Sezer EC (2005) Non-control-data attacks are realistic threats. In: McDaniel PD (ed)Proceedings of the 14th USENIX Security Symposium, Baltimore, MD, USA, July 31 - August 5, 2005.. USENIX Association, Baltimore."},{"key":"58_CR6","unstructured":"Christey, S, Martin RA (2007) Vulnerability Type Distributions in CVE. http:\/\/cve.mitre.org\/docs\/vuln-trends\/vuln-trends.pdf."},{"key":"58_CR7","unstructured":"Common Vulnerabilities and Exposures (CVE) (2020). http:\/\/cve.mitre.org\/."},{"key":"58_CR8","unstructured":"CWE-680: IO2BO Vulnerabilities (2020). http:\/\/cwe.mitre.org\/data\/definitions\/680.html."},{"key":"58_CR9","first-page":"760","volume-title":"34th International Conference on Software Engineering, ICSE 2012, June 2-9, 2012","author":"W Dietz","year":"2012","unstructured":"Dietz, W, Li P, Regehr J, Adve VS (2012) Understanding integer overflow in C\/C++. In: Glinz M, Murphy GC, Pezz\u00e8 M (eds)34th International Conference on Software Engineering, ICSE 2012, June 2-9, 2012, 760\u2013770.. IEEE Computer Society, Zurich."},{"key":"58_CR10","first-page":"989","volume-title":"26th USENIX Security Symposium, USENIX Security 2017, August 16-18, 2017","author":"X Jia","year":"2017","unstructured":"Jia, X, Zhang C, Su P, Yang Y, Huang H, Feng D (2017) Towards efficient heap overflow discovery. In: Kirda E Ristenpart T (eds)26th USENIX Security Symposium, USENIX Security 2017, August 16-18, 2017, 989\u20131006.. USENIX Association, Vancouver."},{"key":"58_CR11","unstructured":"Lattner, C (2012) LLVM: An Infrastructure for Multi-Stage Optimization. http:\/\/llvm.cs.uiuc.edu."},{"key":"58_CR12","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1109\/CGO.2004.1281665","volume-title":"2nd IEEE \/ ACM International Symposium on Code Generation and Optimization (CGO 2004), 20-24 March 2004","author":"C Lattner","year":"2004","unstructured":"Lattner, C, Adve VS (2004) LLVM: A compilation framework for lifelong program analysis & transformation In: 2nd IEEE \/ ACM International Symposium on Code Generation and Optimization (CGO 2004), 20-24 March 2004, 75\u201388.. IEEE Computer Society, San Jose."},{"key":"58_CR13","first-page":"1867","volume-title":"Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS)","author":"K Lu","year":"2019","unstructured":"Lu, K, Hu H (2019) Where does it go?: Refining indirect-call targets with multi-layer type analysis. In: Cavallaro L, Kinder J, Wang X, Katz J (eds)Proceedings of ACM SIGSAC Conference on Computer and Communications Security (CCS), 1867\u20131881.. ACM, London."},{"key":"58_CR14","doi-asserted-by":"crossref","unstructured":"Mingjie X, Shengnan L, Lili X, Feng L, Wei H, Jing M, Xinhua L, Qingjia H (2018) A Light-Weight and Accurate Method of Static Integer-Overflow-to-Buffer-Overflow Vulnerability Detection. In: Fuchun Guo, Xinyi Huang, Moti Yung (eds)Information Security and Cryptology - 14th International Conference, Inscrypt 2018, December 14-17, 2018, Revised Selected Papers, 404\u2013423.. Springer, Fuzhou.","DOI":"10.1007\/978-3-030-14234-6_22"},{"key":"58_CR15","unstructured":"Moy, Y, Bj\u00f8rner N, Sielaff D (2009) Modular bug-finding for integer overflows in the large: Sound, efficient, bit-precise static analysis. Technical report. Technical Report MSR-TR-2009-57, Microsoft Research."},{"key":"58_CR16","unstructured":"(2017) National Institute of Standard and Technology (NIST). SAMATE-software assurance metrics and tool evaluation. http:\/\/samate.nist.gov\/SARD\/testsuite.php."},{"key":"58_CR17","unstructured":"National Vulnerability Database (2020). http:\/\/nvd.nist.gov\/."},{"key":"58_CR18","doi-asserted-by":"crossref","first-page":"577","DOI":"10.1145\/2594291.2594295","volume-title":"ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI \u201914 - June 09 - 11, 2014","author":"B Niu","year":"2014","unstructured":"Niu, B, Tan G (2014) Modular control-flow integrity. In: O\u2019Boyle MFP Pingali K (eds)ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI \u201914 - June 09 - 11, 2014, 577\u2013587.. ACM, Edinburgh."},{"key":"58_CR19","unstructured":"Sotirov, A (2007) Heap feng shui in javascript. https:\/\/www.blackhat.com\/presentations\/bh-usa-07\/Sotirov\/Whitepaper\/bh-usa-07-sotirov-WP.pdf."},{"key":"58_CR20","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1145\/2892208.2892235","volume-title":"Proceedings of the 25th International Conference on Compiler Construction","author":"Y Sui","year":"2016","unstructured":"Sui, Y, Xue J (2016) Svf: interprocedural static value-flow analysis in llvm In: Proceedings of the 25th International Conference on Compiler Construction, 265\u2013266.. Association for Computing Machinery, New York."},{"key":"58_CR21","first-page":"483","volume-title":"Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security, ASIA CCS \u201915, April 14-17, 2015","author":"H Sun","year":"2015","unstructured":"Sun, H, Zhang X, Su C, Zeng Q (2015) Efficient dynamic tracking technique for detecting integer-overflow-to-buffer-overflow vulnerability. In: Bao F, Miller S, Zhou J, Ahn G (eds)Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security, ASIA CCS \u201915, April 14-17, 2015, 483\u2013494.. ACM, Singapore."},{"key":"58_CR22","first-page":"941","volume-title":"Proceedings of the 23rd USENIX Security Symposium, August 20-22, 2014","author":"C Tice","year":"2014","unstructured":"Tice, C, Roeder T, Collingbourne P, Checkoway S, Erlingsson \u00da, Lozano L, Pike G (2014) Enforcing forward-edge control-flow integrity in GCC & LLVM. In: Fu K Jung J (eds)Proceedings of the 23rd USENIX Security Symposium, August 20-22, 2014, 941\u2013955.. USENIX Association, San Diego."},{"key":"58_CR23","unstructured":"Vreugdenhil, P (2020) Pwn2Own 2010 Windows 7 Internet Explorer 8 Exploit. http:\/\/vreugdenhilresearch.nl\/Pwn2Own-2010-Windows7-InternetExplorer8.pdf."},{"key":"58_CR24","first-page":"163","volume-title":"10th USENIX Symposium on Operating Systems Design and Implementation, OSDI 2012, October 8-10, 2012","author":"X Wang","year":"2012","unstructured":"Wang, X, Chen H, Jia Z, Zeldovich N, Kaashoek MF (2012) Improving integer security for systems with KINT. In: Thekkath C Vahdat A (eds)10th USENIX Symposium on Operating Systems Design and Implementation, OSDI 2012, October 8-10, 2012, 163\u2013177.. USENIX Association, Hollywood."},{"key":"58_CR25","doi-asserted-by":"crossref","unstructured":"Wang, Y, Gu D, Xu J, Wen M, Deng L (2010) RICB: integer overflow vulnerability dynamic analysis via buffer overflow. In: Lai X, Gu D, Jin B, Wang Y, Li H (eds)Forensics in Telecommunications, Information, and Multimedia - Third International ICST Conference, e-Forensics 2010, November 11-12, 2010, Revised Selected Papers. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, vol 56, 99\u2013109.. Springer, Shanghai.","DOI":"10.1007\/978-3-642-23602-0_9"},{"key":"58_CR26","volume-title":"Proceedings of the Network and Distributed System Security Symposium, NDSS 2009, 8th February - 11th February 2009","author":"T Wang","year":"2009","unstructured":"Wang, T, Wei T, Lin Z, Zou W (2009) Intscope: Automatically detecting integer overflow vulnerability in X86 binary using symbolic execution In: Proceedings of the Network and Distributed System Security Symposium, NDSS 2009, 8th February - 11th February 2009.. The Internet Society, San Diego."},{"key":"58_CR27","first-page":"247","volume-title":"Research in Attacks, Intrusions, and Defenses - 18th International Symposium, RAID 2015, November 2-4, 2015, Proceedings. LNCS, vol 9404","author":"Y Zhang","year":"2015","unstructured":"Zhang, Y, Sun X, Deng Y, Cheng L, Zeng S, Fu Y, Feng D (2015) Improving accuracy of static integer overflow detection in binary. In: Bos H, Monrose F, Blanc G (eds)Research in Attacks, Intrusions, and Defenses - 18th International Symposium, RAID 2015, November 2-4, 2015, Proceedings. LNCS, vol 9404, 247\u2013269.. Springer, Kyoto."},{"key":"58_CR28","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/978-3-642-15497-3_5","volume-title":"Computer Security \u2013 ESORICS 2010","author":"C Zhang","year":"2010","unstructured":"Zhang, C, Wang T, Wei T, Chen Y, Zou W (2010) Intpatch: Automatically fix integer-overflow-to-buffer-overflow vulnerability at compile-time. In: Gritzalis D, Preneel B, Theoharidou M (eds)Computer Security \u2013 ESORICS 2010, 71\u201386.. Springer, Berlin, Heidelberg."}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-020-00058-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-020-00058-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-020-00058-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,7]],"date-time":"2021-09-07T23:06:25Z","timestamp":1631055985000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-020-00058-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,9,8]]},"references-count":28,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["58"],"URL":"https:\/\/doi.org\/10.1186\/s42400-020-00058-2","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,9,8]]},"assertion":[{"value":"10 July 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 August 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 September 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"18"}}