<<<<<<< HEAD This is the Spinner project page. Released code and contents that we was not able to cover in the paper due to the page limit are placed here.
We carefully selected 27 programs that are known they have input injection vulnerabilities in recent five years and evaluate effectiveness of Spinner using them. This section covers the detailed contents that were not covered through Table 2 in the paper.
Detailed information are shown in Vulnerable_programs.
To show that our instrumentation does not break the original functionalities, we use the test cases and check that they can cover instrumented code snippets and other affected code. This section covers the test cases of evaluated programs.
The test cases are in Test_cases.
This section contains the source code code of Spinner's analysis tools and system call hooking tools.
Detailed contents are in Source_code.
======= This is the Spinner project page. In addition to the code release, we present additional content that are not included in the paper, due to the page limit.
We selected 27 programs with input injection vulnerabilities in the recent five years to evaluate Spinner's effectiveness. This section covers the detailed content that is not covered through Table 2 in the paper.
- Details can be found on
Vulnerable Programs Sub Page.
To show that our instrumentation does not break the original functionalities, we use the test cases and check that they can cover instrumented code snippets and other affected code. This section covers the test cases of evaluated programs.
- Details can be found on
Test Cases Sub Page.
This section contains the source code code of Spinner's analysis tools and system call hooking tools.
- Details can be found on
Source Code Sub Page.
This sub page presents Spinner's trusted command speciication generator, brute-force attacks on static and dynamic randomization approaches, additional details of programs used in evaluation, etc.
- Details can be found on
Supplementary Sub Page.
f12236e5e9c6e4fb3e0b3e8f3dd917f73585f33b