HexVASAN: A Variadic Function Sanitizer

10/04/2017
1:30 pm - 4:00 pm
Expo Hall/Career Fair

Objective: Inspiration
Audience Level: All
Session Type: Poster

Variadic functions introduce an implicitly defined contract between the caller and callee. Failing to enforce the contract correctly leads to a vulnerability. Current tools do not find variadic function type errors or prevent attackers from exploiting calls to variadic functions. Unfortunately, variadic functions are prevalent. Here, I propose a new sanitizer to address this attack vector.

Speaker(s)

, Graduate Research Assistant, Purdue University