Skip to main navigation Skip to search Skip to main content

Analyzing Semantic Correctness with Symbolic Execution: A Case Study on PKCS#1 v1.5 Signature Verification

  • Sze Yiu Chau
  • , Moosa Yahyazadeh
  • , Omar Chowdhury
  • , Aniket Kate
  • , Ninghui Li
  • Purdue University
  • University of Iowa

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

21 Scopus citations

Abstract

We discuss how symbolic execution can be used to not only find low-level errors but also analyze the semantic correctness of protocol implementations. To avoid manually crafting test cases, we propose a strategy of meta-level search, which leverages constraints stemmed from the input formats to automatically generate concolic test cases. Additionally, to aid root-cause analysis, we develop constraint provenance tracking (CPT), a mechanism that associates atomic sub-formulas of path constraints with their corresponding source level origins. We demonstrate the power of symbolic analysis with a case study on PKCS#1 v1.5 signature verification. Leveraging meta-level search and CPT, we analyzed 15 recent open-source implementations using symbolic execution and found semantic flaws in 6 of them. Further analysis of these flaws showed that 4 implementations are susceptible to new variants of the Bleichenbacher low-exponent RSA signature forgery. One implementation suffers from potential denial of service attacks with purposefully crafted signatures. All our findings have been responsibly shared with the affected vendors. Among the flaws discovered, 6 new CVEs have been assigned to the immediately exploitable ones.

Original languageEnglish
Title of host publication26th Annual Network and Distributed System Security Symposium, NDSS 2019
PublisherThe Internet Society
ISBN (Electronic)189156255X, 9781891562556
DOIs
StatePublished - 2019
Event26th Annual Network and Distributed System Security Symposium, NDSS 2019 - San Diego, United States
Duration: Feb 24 2019Feb 27 2019

Publication series

Name26th Annual Network and Distributed System Security Symposium, NDSS 2019

Conference

Conference26th Annual Network and Distributed System Security Symposium, NDSS 2019
Country/TerritoryUnited States
CitySan Diego
Period02/24/1902/27/19

Fingerprint

Dive into the research topics of 'Analyzing Semantic Correctness with Symbolic Execution: A Case Study on PKCS#1 v1.5 Signature Verification'. Together they form a unique fingerprint.

Cite this