首页> 外文会议>IEEE European Symposium on Security and Privacy Workshops >Security across abstraction layers: old and new examples
【24h】

Security across abstraction layers: old and new examples

机译:跨抽象层的安全性:新旧示例

获取原文

摘要

A common technique for building ICT systems is to build them as successive layers of bstraction: for instance, the Instruction Set Architecture (ISA) is an abstraction of the hardware, and compilers or interpreters build higher level abstractions on top of the ISA.The functionality of an ICT application can often be understood by considering only a single level of abstraction. For instance the source code of the application defines the functionality using the level of abstraction of the source programming language. Functionality can be well understood by just studying this source code.Many important security issues in ICT system however are cross-layer issues: they can not be understood by considering the system at a single level of abstraction, but they require understanding how multiple levels of abstraction are implemented. Attacks may rely on, or exploit, implementation details of one or more layers below the source code level of abstraction.The purpose of this paper is to illustrate this cross-layer nature of security by discussing old and new examples of cross-layer security issues, and by providing a classification of these issues.
机译:构建ICT系统的一种常见技术是将它们构建为连续的抽象层:例如,指令集体系结构(ISA)是硬件的抽象,而编译器或解释器则在ISA之上构建更高级别的抽象。通常只考虑一个抽象级别就可以理解ICT应用程序的特性。例如,应用程序的源代码使用源编程语言的抽象级别定义功能。仅研究此源代码就可以很好地理解功能。但是,ICT系统中的许多重要安全问题都是跨层的问题:无法通过在单个抽象级别上考虑系统来理解它们,但是它们需要了解如何在多个抽象级别上进行理解。实现抽象。攻击可能依赖或利用抽象源代码级别以下一层或多层的实现细节。本文的目的是通过讨论新的和新的跨层安全性问题示例来说明这种跨层安全性。 ,并提供这些问题的分类。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号