Virtualization and Static Analysis to Detect Memory Overwriting Vulnerabilities

Award Information
Agency:
Department of Homeland Security
Branch
n/a
Amount:
$96,155.00
Award Year:
2009
Program:
SBIR
Phase:
Phase I
Contract:
N10PC20012
Award Id:
89996
Agency Tracking Number:
0921099
Solicitation Year:
n/a
Solicitation Topic Code:
n/a
Solicitation Number:
n/a
Small Business Information
2040 Tremont Road, Charlottesville, VA, 22911-
Hubzone Owned:
Y
Minority Owned:
Y
Woman Owned:
Y
Duns:
830972647
Principal Investigator:
Clark Coleman
(434) 284-3002
clark.coleman@att.net
Business Contact:
Jack Davidson
(434) 242-4280
davidsonjw@acm.org
Research Institution:
n/a
Abstract
Memory overwriting vulnerabilities (buffer overflow, format string, double free, integer overflow, etc.) continue to plague commercial and government software, providing avenues for attackers to gain unauthorized control over computer systems. Testing tools are needed that will find vulnerabilities so that fixes can be applied before deployment. Existing vulnerability analyses often rely exclusively on either static or dynamic analysis tools, each of which has its strengths and weaknesses. Many defenses require source code for the application being tested, which is not practical for final acceptance testing by software consumers, who are often not allowed access to the source code of the software vendor. The proposed research will enhance and integrate prior static and dynamic analysis tools to enable software producers and consumers to accomplish two important objectives: (1) To strengthen software testing with respect to exercising potentially vulnerable code, and (2) to identify and fix memory overwriting vulnerabilities before software deployment. Only the binary form of the tested software will be needed. The result of the eventual Phase II effort will be an acceptance testing tool that will be commercialized for Linux and Windows systems.

* information listed above is at the time of submission.

Agency Micro-sites


SBA logo

Department of Agriculture logo

Department of Commerce logo

Department of Defense logo

Department of Education logo

Department of Energy logo

Department of Health and Human Services logo

Department of Homeland Security logo

Department of Transportation logo

Enviromental Protection Agency logo

National Aeronautics and Space Administration logo

National Science Foundation logo
US Flag An Official Website of the United States Government