Write a Blog >>
ISSTA 2020
Sat 18 - Wed 22 July 2020
Wed 22 Jul 2020 10:50 - 11:10 at Zoom - BINARY ANALYSIS Chair(s): Junaid Haroon Siddiqui

The binary-level function matching has been widely used to detect whether there are 1-day vulnerabilities in released programs.However, the high false positive is a challenge for current function matching solutions, since the vulnerable function is highly similar to its corresponding patched version.In this paper, the Binary X-Ray (BinXray), a patch based vulnerability matching approach, is proposed to identify the specific 1-day vulnerabilities in target programs accurately and effectively. In the preparing step, a basic block mapping algorithm is designed to extract the signature of a patch, by comparing the given vulnerable and patched programs. The signature is represented as a set of basic block traces. In the detection step, the patching semantics is applied to reduce irrelevant basic block traces to speed up the signature searching. The trace similarity is also designed to identify whether a target program is patched. In experiments, 12 real software projects related to 479 CVEs are collected. BinXray achieves 93.31% accuracy and the analysis speed is only 296.17ms per function, outperforming the state-of-the-art works.

Wed 22 Jul

Displayed time zone: Tijuana, Baja California change

10:50 - 11:50
BINARY ANALYSISTechnical Papers at Zoom
Chair(s): Junaid Haroon Siddiqui

Public Live Stream/Recording. Registered participants should join via the Zoom link distributed in Slack.

10:50
20m
Talk
Patch Based Vulnerability Matching for Binary Programs
Technical Papers
Yifei Xu , Zhengzi Xu , Bihuan Chen Fudan University, Fu Song , Yang Liu Nanyang Technological University, Singapore, Ting Liu Xi'an Jiaotong University
DOI Media Attached
11:10
20m
Talk
Identifying Java Calls in Native Code via Binary ScanningArtifacts AvailableArtifacts Evaluated – Functional
Technical Papers
George Fourtounis University of Athens, Leonidas Triantafyllou University of Athens, Yannis Smaragdakis University of Athens, Greece
DOI Media Attached
11:30
20m
Talk
An Empirical Study on ARM Disassembly Tools
Technical Papers
Muhui Jiang , Yajin Zhou Zhejiang University, Xiapu Luo The Hong Kong Polytechnic University, Ruoyu Wang , Yang Liu Nanyang Technological University, Singapore, Kui Ren
DOI