TY - GEN
T1 - New Version, New Answer
T2 - 3rd IEEE International Conference on Cyber Security and Resilience, CSR 2023
AU - Reinhold, Ann Marie
AU - Weber, Travis
AU - Lemak, Colleen
AU - Reimanis, Derek
AU - Izurieta, Clemente
N1 - Funding Information:
Ann Marie Reinhold, Derek Reimanis, and Clemente Izurieta: Funded by the Department of Homeland Security (DHS) Science and Technology (S&T) Directorate under contract number 70RSAT22CB0000005. Travis Weber and Colleen Lemack: Portions of this material are based upon work supported by the United States National Science Foundation under Grant No. CCF-1947750. Any opinions, findings, and conclusions or recommendations expressed in this material are those of the authors and do not necessarily reflect the views of the National Science Foundation and DHS S&T.
Publisher Copyright:
© 2023 IEEE.
PY - 2023/8/28
Y1 - 2023/8/28
N2 - Automated detection of vulnerabilities and weaknesses in binary code is a critical need at the frontier of cybersecurity research. Cybersecurity static-analysis tools aim to detect and enumerate vulnerabilities and weaknesses. Two popular tools are CVE Binary Tool (cve-bin-tool) and cwe-checker. Cve-bin-tool reports vulnerabilities using Common Vulnerabilities and Exposures (CVE) whereas cwe-checker reports weaknesses using Common Weakness Enumeration (CWE). Despite widespread use, the consistency with which these tools report vulnerabilities and weaknesses (herein, 'findings') was unaddressed. We conducted a systematic investigation of 660 unique binaries taken from a Kali Linux distribution, evaluated each binary with multiple versions of the static-analysis tools, and investigated how the findings changed according to the version of the static-analysis tool used. We expected some variation in findings commensurate with the software-development life cycle. However, the number and magnitude of the changes in findings reported across versions were substantial. New versions gave new answers.
AB - Automated detection of vulnerabilities and weaknesses in binary code is a critical need at the frontier of cybersecurity research. Cybersecurity static-analysis tools aim to detect and enumerate vulnerabilities and weaknesses. Two popular tools are CVE Binary Tool (cve-bin-tool) and cwe-checker. Cve-bin-tool reports vulnerabilities using Common Vulnerabilities and Exposures (CVE) whereas cwe-checker reports weaknesses using Common Weakness Enumeration (CWE). Despite widespread use, the consistency with which these tools report vulnerabilities and weaknesses (herein, 'findings') was unaddressed. We conducted a systematic investigation of 660 unique binaries taken from a Kali Linux distribution, evaluated each binary with multiple versions of the static-analysis tools, and investigated how the findings changed according to the version of the static-analysis tool used. We expected some variation in findings commensurate with the software-development life cycle. However, the number and magnitude of the changes in findings reported across versions were substantial. New versions gave new answers.
UR - https://www.scopus.com/pages/publications/85171779690
UR - https://www.mendeley.com/catalogue/3a753c4d-41a8-3d03-ae9a-879af9dbe8b6/
U2 - 10.1109/CSR57506.2023.10224930
DO - 10.1109/CSR57506.2023.10224930
M3 - Conference contribution
AN - SCOPUS:85171779690
T3 - Proceedings of the 2023 IEEE International Conference on Cyber Security and Resilience, CSR 2023
SP - 28
EP - 35
BT - Proceedings of the 2023 IEEE International Conference on Cyber Security and Resilience, CSR 2023
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 31 July 2023 through 2 August 2023
ER -