首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >A Memory-Access Validation Scheme against Payload Injection Attacks
【24h】

A Memory-Access Validation Scheme against Payload Injection Attacks

机译:一种针对有效载荷注入攻击的内存访问验证方案

获取原文
获取原文并翻译 | 示例
           

摘要

The authenticity of a piece of data or an instruction is crucial in mitigating threats from various forms of software attack. In spite of the various forms of protection against malicious attacks exploiting spurious data, adversaries have been successful in circumventing such protection. This paper proposes a memory-access validation scheme that manages information on spurious data at the granularity of the cache line size. A validation unit based on the proposed scheme answers queries from other components in the processor so that spurious data can be blocked before control flow diversion. We describe the design of this validation unit as well as its integration into the memory hierarchy of a modern processor and assess its memory requirement and performance impact with two simulators. The experimental results show that our scheme is able to detect synthesized payload injection attacks and to manage taint information with a moderate memory overhead under an acceptable performance impact.
机译:一条数据或一条指令的真实性对于缓解各种形式的软件攻击带来的威胁至关重要。尽管针对利用虚假数据进行的恶意攻击采取了多种保护措施,但攻击者已成功地绕过了这种保护措施。本文提出了一种内存访问验证方案,该方案以缓存行大小的粒度管理有关虚假数据的信息。基于所提出的方案的验证单元回答来自处理器中其他组件的查询,以便可以在控制流转移之前阻止虚假数据。我们描述了此验证单元的设计及其与现代处理器的内存层次结构的集成,并使用两个模拟器评估了其内存需求和性能影响。实验结果表明,我们的方案能够在可接受的性能影响下以适当的内存开销检测合成的有效载荷注入攻击并管理污点信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号