首页> 外文OA文献 >Security protection and checking for embedded system integration against buffer overflow attacks via hardware/software
【2h】

Security protection and checking for embedded system integration against buffer overflow attacks via hardware/software

机译:通过硬件/软件进行安全保护并检查嵌入式系统集成,以防止缓冲区溢出攻击

摘要

With more embedded systems networked, it becomes an important problem to effectively defend embedded systems against buffer overflow attacks. Due to the increasing complexity and strict requirements, off-the-shelf software components are widely used in embedded systems, especially for military and other critical applications. Therefore, in addition to effective protection, we also need to provide an approach for system integrators to efficiently check whether software components have been protected. In this paper, we propose the HSDefender (Hardware/Software Defender) technique to perform protection and checking together. Our basic idea is to design secure call instructions so systems can be secured and checking can be easily performed. In the paper, we classify buffer overflow attacks into two categories and provide two corresponding defending strategies. We analyze the HSDefender technique with respect to hardware cost, security, and performance. We experiment with our HSDefender technique on the SimpleScalar/ARM simulator with benchmarks from MiBench, an embedded benchmark suite. The results show that our HSDefender technique can defend a system against more types of buffer overflow attacks with less overhead compared with the previous work.
机译:随着更多嵌入式系统的联网,有效地保护嵌入式系统免受缓冲区溢出攻击已成为一个重要的问题。由于日益增加的复杂性和严格的要求,现成的软件组件广泛用于嵌入式系统中,尤其是在军事和其他关键应用中。因此,除了有效的保护外,我们还需要为系统集成商提供一种有效检查软件组件是否已受到保护的方法。在本文中,我们提出了HSDefender(硬件/软件防御者)技术来一起执行保护和检查。我们的基本思想是设计安全的呼叫指示,以便可以保护系统安全并轻松进行检查。在本文中,我们将缓冲区溢出攻击分为两类,并提供了两种相应的防御策略。我们从硬件成本,安全性和性能方面分析了HSDefender技术。我们在带有嵌入式基准测试套件MiBench的基准的SimpleScalar / ARM模拟器上对HSDefender技术进行了实验。结果表明,与以前的工作相比,我们的HSDefender技术可以以更少的开销保护系统免受更多类型的缓冲区溢出攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号