Hector: Detecting resource-release omission faults in error-handling code for systems software - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

Hector: Detecting resource-release omission faults in error-handling code for systems software

Résumé

Omitting resource-release operations in systems error handling code can lead to memory leaks, crashes, and deadlocks. Finding omission faults is challenging due to the difficulty of reproducing system errors, the diversity of system resources, and the lack of appropriate abstractions in the C language. To address these issues, numerous approaches have been proposed that globally scan a code base for common resource-release operations. Such macroscopic approaches are notorious for their many false positives, while also leaving many faults undetected. We propose a novel microscopic approach to finding resource-release omission faults in systems software. Rather than generalizing from the entire source code, our approach focuses on the error-handling code of each function. Using our tool, Hector, we have found over 370 faults in six systems software projects, including Linux, with a 23% false positive rate. Some of these faults allow an unprivileged malicious user to crash the entire system.
Fichier principal
Vignette du fichier
dsn2013.pdf (462.05 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00918079 , version 1 (19-05-2016)

Licence

Copyright (Tous droits réservés)

Identifiants

Citer

Suman Saha, Jean-Pierre Lozi, Gaël Thomas, Julia Lawall, Gilles Muller. Hector: Detecting resource-release omission faults in error-handling code for systems software. DSN 2013 - 43rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN), IEEE/IFIP, Jun 2013, Budapest, Hungary. pp.1-12, ⟨10.1109/DSN.2013.6575307⟩. ⟨hal-00918079⟩
176 Consultations
388 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More