首页> 外文OA文献 >StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks
【2h】

StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks

机译:stackGuard:自动自适应检测和防止缓冲区溢出攻击

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

This paper presents a systematic solution to the persistent problem of buffer overflow attacks. Buffer overflow attacks gained notoriety in 1988 as part of the Morris Worm incident on the Internet. While it is fairly simple to fix individual buffer overflow vulnerabilities, buffer overflow attacks continue to this day. Hundreds of attacks have been discovered, and while most of the obvious vulnerabilities have now been patched, more sophisticated buffer overflow attacks continue to emerge.We describe StackGuard: a simple compiler technique that virtually eliminates buffer overflow vulnerabilities with only modest performance penalties. Privileged programs that are recompiled with the StackGuard compiler extension no longer yield control to the attacker, but rather enter a fail-safe state.These programs require no source code changes at all, and are binary-compatible with existing operating systems and libraries. We describe the compiler technique (a simple patch to gcc), as well as a set of variations on the technique that tradeoff between penetration resistance and performance. We present experimental results of both the penetration resistance and the performance impact of this technique.
机译:本文提出了解决缓冲区溢出攻击的持久性问题的系统解决方案。 1988年,由于Internet上的Morris Worm事件,缓冲区溢出攻击声名狼藉。尽管修复单个缓冲区溢出漏洞非常简单,但缓冲区溢出攻击一直持续到今天。已经发现了数百种攻击,并且尽管现在已修补了大多数明显的漏洞,但仍在继续出现更复杂的缓冲区溢出攻击。我们介绍了StackGuard:一种简单的编译器技术,实际上消除了缓冲区溢出漏洞,仅对性能造成了轻微的影响。使用StackGuard编译器扩展重新编译的特权程序不再对攻击者产生控制权,而是进入故障安全状态。这些程序完全不需要更改源代码,并且与现有的操作系​​统和库二进制兼容。我们描述了编译器技术(一个简单的gcc补丁),以及在抗渗透性和性能之间进行权衡的该技术的一组变体。我们介绍了这项技术的抗穿透性和性能影响的实验结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号