首页> 外文会议>Nordic conference on secure IT systems >A Survey on Internal Interfaces Used by Exploits and Implications on Interface Diversification
【24h】

A Survey on Internal Interfaces Used by Exploits and Implications on Interface Diversification

机译:漏洞利用内部接口的调查及其对接口多样化的启示

获取原文

摘要

The idea of interface diversification is that internal interfaces in the system are transformed into unique secret instances. On one hand, the trusted programs in the system are accordingly modified so that they can use the diversified interfaces. On the other hand, the malicious code injected into a system does not know the diversification secret, that is the language of the diversified system, and thus it is rendered useless. Based on our study of 500 exploits, this paper surveys the different interfaces that are targeted in malware attacks and can potentially be diversified in order to prevent the malware from reaching its goals. In this study, we also explore which of the identified interfaces have already been covered in existing diversification research and which interfaces should be considered in future research. Moreover, we discuss the benefits and drawbacks of diversifying these interfaces. We conclude that diversification of various internal interfaces could prevent or mitigate roughly 80% of the analyzed exploits. Most interfaces we found have already been diversified as proof-of-concept implementations but diversification is not widely used in practical systems.
机译:接口多样化的想法是将系统中的内部接口转换为唯一的秘密实例。一方面,对系统中的受信任程序进行了相应的修改,以便它们可以使用多样化的接口。另一方面,注入到系统中的恶意代码不知道多样化秘密(即多样化系统的语言),因此使其变得无用。基于对500个漏洞的研究,本文调查了针对恶意软件攻击的不同接口,并可能对其进行多样化以防止恶意软件达到其目标。在本研究中,我们还将探讨现有的多元化研究中已经涵盖了哪些已确定的接口,以及在未来的研究中应考虑哪些接口。此外,我们讨论了使这些接口多样化的优点和缺点。我们得出的结论是,各种内部接口的多样化可以防止或减轻大约80%的分析利用。我们发现,大多数接口已经作为概念证明的实现而多样化,但是多样化在实际系统中并未得到广泛使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号