Analyzing Semantic Correctness with Symbolic Execution: A Case Study on PKCS#1 v1.5 Signature Verification
Sze Yiu Chau, Moosa Yahyazadeh, Omar Chowdhury, Aniket Kate, Ninghui Li
摘要
We discuss how symbolic execution can be used to not only find low-level errors but also analyze the semantic correctness of protocol implementations. To avoid manually crafting test cases, we propose a strategy of meta-level search, which leverages constraints stemmed from the input formats to automatically generate concolic test cases. Additionally, to aid root-cause analysis, we develop constraint provenance tracking (CPT), a mechanism that associates atomic sub-formulas of path constraints with their corresponding source level origins. We demonstrate the power of symbolic analysis with a case study on PKCS#1 v1.5 signature verification. Leveraging meta-level search and CPT, we analyzed 15 recent open-source implementations using symbolic execution and found semantic flaws in 6 of them. Further analysis of these flaws showed that 4 implementations are susceptible to new variants of the Bleichenbacher lowexponent RSA signature forgery. One implementation suffers from potential denial of service attacks with purposefully crafted signatures. All our findings have been responsibly shared with the affected vendors. Among the flaws discovered, 6 new CVEs have been assigned to the immediately exploitable ones.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- ARCUS: Symbolic Root Cause Analysis of Exploits in Production SystemsCarter Yagemann, Matthew Pruett, Simon P. Chung, Kennon Bittick 等USENIX Security 2021 · 被引用 42 次
- Learning to Explore Paths for Symbolic ExecutionJingxuan He, Gishor Sivanrupan, Petar Tsankov, Martin T. VechevCCS 2021 · 被引用 39 次
- Automated Bug Hunting With Data-Driven Symbolic Root Cause AnalysisCarter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke LeeCCS 2021 · 被引用 17 次
- Themis: Ambiguity-Aware Network Intrusion Detection based on Symbolic Model ComparisonZhongjie Wang, Shitong Zhu, Keyu Man, Pengxiong Zhu 等CCS 2021 · 被引用 6 次
- Morpheus: Bringing The (PKCS) One To Meet the OracleMoosa Yahyazadeh, Sze Yiu Chau, Li Li, Man Hong Hue 等CCS 2021 · 被引用 5 次
它引用的顶会 Paper3
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 被引用 136 次
- Return Of Bleichenbacher's Oracle Threat (ROBOT)Hanno Böck, Juraj Somorovsky, Craig YoungUSENIX Security 2018 · 被引用 69 次
- SymCerts: Practical Symbolic Execution for Exposing Noncompliance in X.509 Certificate Validation ImplementationsSze Yiu Chau, Omar Chowdhury, Md. Endadul Hoque, Huangyi Ge 等S&P 2017 · 被引用 67 次
相关 Paper
- Concrete Constraint Guided Symbolic ExecutionYue Sun, Guowei Yang, Shichao Lv, Zhi Li 等ICSE 2024 · 被引用 3 次
- Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use SignaturesDennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf SasseCCS 2019 · 被引用 53 次
- Engineering a Formally Verified Automated Bug FinderArthur Correnson, Dominic SteinhöfelFSE 2023 · 被引用 6 次
- SymRadar: PoC-Centered Bounded Verification for Vulnerability RepairSeungheon Han, YoungJae Kim, Yeseung Lee, Jooyong YiICSE 2026 · 被引用 1 次
- CryptoBap: A Binary Analysis Platform for Cryptographic ProtocolsFaezeh Nasrabadi, Robert Künnemann, Hamed NematiCCS 2023 · 被引用 3 次
