首页> 外文会议> >A practical framework for dynamically immunizing software security vulnerabilities
【24h】

A practical framework for dynamically immunizing software security vulnerabilities

机译:动态消除软件安全漏洞的实用框架

获取原文

摘要

Many security attacks are caused by software vulnerabilities such as buffer overflow. How to eliminate or mitigate these vulnerabilities, in particular with unstoppable software, is a great challenge for security researchers and practitioners. In this paper, we propose a practical framework to immunize software security vulnerabilities on the fly. We achieve the vulnerability immunization by using a security antibody, which can be implemented independently from the protected software and is used to defend against vulnerability exploitation attacks. And we employ in-core patching technique to attach the antibody quietly into running process, and hence we neither need to re-compile nor re-execute the protected software. The effectiveness of our framework depends on the effectiveness of the antibody that is implemented by redirecting flaw functions into secure ones. As a proof of concept, we have built a prototype and applied it to prevent the software from buffer overflow attacks. Preliminary experimental results show that our framework is practical and efficient for the dynamical immunization of software security vulnerabilities.
机译:许多安全攻击是由软件漏洞(例如缓冲区溢出)引起的。对于安全研究人员和从业人员而言,如何消除或缓解这些漏洞(尤其是使用不可阻挡的软件)是一个巨大的挑战。在本文中,我们提出了一个实用的框架来即时消除软件安全漏洞。我们通过使用安全抗体实现漏洞免疫,该抗体可以独立于受保护的软件实施,并用于防御漏洞利用攻击。而且,我们采用核心修补技术将抗体安静地连接到运行过程中,因此,我们无需重新编译或重新执行受保护的软件。我们框架的有效性取决于通过将缺陷功能重定向到安全功能而实现的抗体的有效性。作为概念验证,我们构建了一个原型并将其应用于防止软件遭受缓冲区溢出攻击的情况。初步实验结果表明,我们的框架对于动态免疫软件安全漏洞是实用且有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号