首页> 外文会议>IEEE International Conference on Consumer Electronics - Berlin >A method for system calls sandboxing based on atomic trusted code region
【24h】

A method for system calls sandboxing based on atomic trusted code region

机译:一种基于原子可信代码区域的系统调用沙箱的方法

获取原文

摘要

This paper presents a new algorithm for the sandboxing system calls based on the atomic trusted code region. The algorithm successfully protects against any kind of code-injection attacks as well as any kind of mimicry attack including known-address attacks and scanning attacks. The algorithm is lightweight and simple. The implementation of algorithm does not need any change on an untrusted machine code and does not need extensive changes on system source code. Whole security policy could be enforced in user space as a plug-in, which gives great flexibility.
机译:本文提出了一种基于原子可信代码区域的沙盒系统调用新算法。该算法成功地防御了任何类型的代码注入攻击以及包括已知地址攻击和扫描攻击在内的任何模仿攻击。该算法轻巧简单。算法的实现不需要在不受信任的机器代码上进行任何更改,也不需要在系统源代码上进行大量更改。整个安全策略可以作为插件在用户空间中强制实施,从而提供了极大的灵活性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号