首页> 外文会议>International Conference on Electronics, Mechanics, Culture and Medicine >Eternal War in Software Security: A Survey of Control Flow Protection
【24h】

Eternal War in Software Security: A Survey of Control Flow Protection

机译:软件安全永恒战争:控制流动保护调查

获取原文

摘要

Software security is the cornerstone of computer system security. Among all the elements consisting of software security, control flow protection is undoubtedly the most important one. Once the process's control flow is hijacked, attacker can manipulate it to implement a variety of malicious acts and break through other protection mechanisms which ultimately lead to the control of the entire system. This paper will present a series of offensive and defensive technologies about Control Flow Protection which have been developed in the past three decades. The paper will elaborate the causes of their emergence, explain the principle of their implement, and compare the security and performance of their method. Additionally, it will introduce some other technologies applied in the progress of attack and mitigation, such as program analysis, virtual memory management, machine learning and so on. Through those above illustration and analysis, the paper summarizes three primary suggestions which not only can enlighten security engineers on the design of new methods, but also can help general developers to estimate their software's robustness, practicability and performance.
机译:软件安全是计算机系统安全的基石。在由软件安全组成的所有元素中,控制流动保护无疑是最重要的。一旦过程的控制流量被劫持,攻击者就可以操纵它来实现各种恶意的行为并突破其他保护机制,最终导致整个系统的控制。本文将展示一系列关于控制流动保护的令人反感和防御技术,这是过去三十年来开发的。本文将详细阐述其出现的原因,解释其实施原则,并比较其方法的安全性和表现。此外,它将介绍在攻击和缓解过程中应用的其他技术,例如程序分析,虚拟内存管理,机器学习等。通过上述图解和分析,本文总结了三个主要建议,这些建议不仅可以开明安全工程师对新方法的设计,而且还可以帮助普通开发人员估算其软件的鲁棒性,实用性和性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号