Cultural advice

The Australian National University acknowledges, celebrates and pays our respects to the Ngunnawal and Ngambri people of the Canberra region and to all First Nations Australians on whose traditional lands we meet and work, and whose cultures are among the oldest continuing cultures in human history.

Aboriginal and Torres Strait Islander peoples are advised that ANU Library collections may include images, names, voices, and other representations of deceased persons.

Material in the collection may contain terms, language or views that reflect the period in which the item was created and may be considered inappropriate today.

Topology-Inspired Method Recovers Obfuscated Term Information From Induced Software Call-Stacks

dc.contributor.authorMaggs, Kelly
dc.contributor.authorRobins, Vanessa
dc.date.accessioned2023-06-30T02:07:00Z
dc.date.available2023-06-30T02:07:00Z
dc.date.issued2021-05-28
dc.date.updated2022-04-10T08:18:22Z
dc.description.abstractFuzzing is a systematic large-scale search for software vulnerabilities achieved by feeding a sequence of randomly mutated input files to the program of interest with the goal being to induce a crash. The information about inputs, software execution traces, and induced call stacks (crashes) can be used to pinpoint and fix errors in the code or exploited as a means to damage an adversary’s computer software. In black box fuzzing, the primary unit of information is the call stack: a list of nested function calls and line numbers that report what the code was executing at the time it crashed. The source code is not always available in practice, and in some situations even the function names are deliberately obfuscated (i.e., removed or given generic names). We define a topological object called the call-stack topology to capture the relationships between module names, function names and line numbers in a set of call stacks obtained via black-box fuzzing. In a proof-of-concept study, we show that structural properties of this object in combination with two elementary heuristics allow us to build a logistic regression model to predict the locations of distinct function names over a set of call stacks. We show that this model can extract function name locations with around 80% precision in data obtained from fuzzing studies of various linux programs. This has the potential to benefit software vulnerability experts by increasing their ability to read and compare call stacks more efficiently.en_AU
dc.description.sponsorshipKM received funding from the Australian Commonwealth Department of Defense under the project title "Mathematical methods for analysis and classification of call-stack data sets". VR was supported by ARC Future Fellowship FT140100604 in the early stages of the project.en_AU
dc.format.mimetypeapplication/pdfen_AU
dc.identifier.citationMaggs K and Robins V (2021) Topology-Inspired Method Recovers Obfuscated Term Information From Induced Software Call-Stacks. Front. Appl. Math. Stat. 7:668082. doi: 10.3389/fams.2021.668082en_AU
dc.identifier.issn2297-4687en_AU
dc.identifier.urihttp://hdl.handle.net/1885/293795
dc.language.isoen_AUen_AU
dc.provenanceThis is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.en_AU
dc.publisherFrontiers Research Foundationen_AU
dc.relationhttp://purl.org/au-research/grants/arc/FT140100604en_AU
dc.rights© 2021 Maggs and Robinsen_AU
dc.sourceFrontiers in Applied Mathematics and Statisticsen_AU
dc.subjectfuzzingen_AU
dc.subjectcrash-triageen_AU
dc.subjectsoftware vulnerability researchen_AU
dc.subjectcall-stack analysisen_AU
dc.subjecttopologyen_AU
dc.subjectTDAen_AU
dc.subjectspecialization pre-orderen_AU
dc.titleTopology-Inspired Method Recovers Obfuscated Term Information From Induced Software Call-Stacksen_AU
dc.typeJournal articleen_AU
dcterms.accessRightsOpen Accessen_AU
dcterms.dateAccepted2021-05-03
local.bibliographicCitation.lastpage13en_AU
local.bibliographicCitation.startpage1en_AU
local.contributor.affiliationMaggs, Kelly, College of Science, ANUen_AU
local.contributor.affiliationRobins, Vanessa, College of Science, ANUen_AU
local.contributor.authoruidMaggs, Kelly, u6741476en_AU
local.contributor.authoruidRobins, Vanessa, u9213671en_AU
local.description.notesImported from ARIESen_AU
local.identifier.absfor490503 - Computational statisticsen_AU
local.identifier.absseo280118 - Expanding knowledge in the mathematical sciencesen_AU
local.identifier.ariespublicationa383154xPUB19759en_AU
local.identifier.citationvolume7en_AU
local.identifier.doi10.3389/fams.2021.668082en_AU
local.identifier.scopusID2-s2.0-85107746038
local.publisher.urlhttps://www.frontiersin.org/en_AU
local.type.statusPublished Versionen_AU

Downloads

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
fams-07-668082.pdf
Size:
2.33 MB
Format:
Adobe Portable Document Format
Description: