首页> 外文会议> >Low-threat security patches and tools
【24h】

Low-threat security patches and tools

机译:低威胁的安全补丁和工具

获取原文

摘要

We consider the problem of distributing potentially dangerous information to a number of competing parties. As a prime example, we focus on the issue of distributing security patches to software. These patches implicitly contain vulnerability information that may be abused to jeopardize the security of other systems. When a vendor supplies a binary program patch, different users may receive it at different times. The differential application times of the patch create a window of vulnerability until all users have installed the patch. An abuser might analyze the binary patch before others install it. Armed with this information, he might be able to abuse another user's machine. A related situation occurs in the deployment of security tools. However, many tools will necessarily encode vulnerability information or explicit information about security "localisms". This information may be reverse-engineered and used against systems. We discuss several ways in which security patches and tools may be made safer. Among these are: customizing patches to apply to only one machine; disguising patches to hinder their interpretation; synchronizing patch distribution to shrink the window of vulnerability; applying patches automatically; and using cryptoprocessors with enciphered operating systems. We conclude with some observations on the utility and effectiveness of these methods.
机译:我们考虑将潜在危险信息分发给多个竞争方的问题。举一个主要的例子,我们专注于将安全补丁分发给软件的问题。这些修补程序隐式包含漏洞信息,这些漏洞信息可能会被滥用以危害其他系统的安全性。当供应商提供二进制程序修补程序时,不同的用户可能会在不同的时间收到它。补丁程序的不同应用时间会创建一个漏洞窗口,直到所有用户都安装了补丁程序为止。滥用者可能会在其他人安装二进制补丁之前对其进行分析。掌握了这些信息,他也许可以滥用其他用户的计算机。在安全工具的部署中会发生相关情况。但是,许多工具必须对有关安全性“局部性”的漏洞信息或显式信息进行编码。此信息可能经过逆向工程,并针对系统使用。我们讨论了使安全补丁和工具更安全的几种方法。其中包括:定制补丁程序以仅应用于一台计算机;掩盖补丁以阻碍其解释;同步补丁分发以缩小漏洞窗口;自动应用补丁;并将加密处理器与加密的操作系统配合使用。最后,我们对这些方法的实用性和有效性进行了一些观察。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号