首页> 外国专利> Heap buffer overflow exploitation prevention system and method

Heap buffer overflow exploitation prevention system and method

机译:堆缓冲区溢出利用预防系统和方法

摘要

A method includes stalling a call to a heap allocation function originating from a request by an application for a block of heap buffer, predicting a block of the heap buffer to fulfill the request, and determining if a forward link (F-link) and a backward link (B-link) of the predicted block are addresses within a heap segment associated with the predicted block. If a determination is made that the F-link or the B-link point outside the associated heap segment, e.g., have been overwritten by a heap buffer overflow attack, corrective action is taken to correct the stray F-link or B-link. After the corrective action is taken, the heap allocation function call is released and the block of heap buffer is allocated. In this manner, a heap buffer overflow attack is defeated.
机译:一种方法包括:暂停从应用程序对堆缓冲区块的请求发起的对堆分配函数的调用;预测堆缓冲区的块满足请求;以及确定前向链接(F-link)和预测块的反向链接(B-link)是与预测块关联的堆段内的地址。如果确定相关联的堆段外部的F-link或B-link点已被堆缓冲区溢出攻击所覆盖,则应采取纠正措施来纠正杂散的F-link或B-link。采取纠正措施后,将释放堆分配函数调用,并分配堆缓冲区块。通过这种方式,可以消除堆缓冲区溢出攻击。

著录项

  • 公开/公告号US7328323B1

    专利类型

  • 公开/公告日2008-02-05

    原文格式PDF

  • 申请/专利权人 MATTHEW CONOVER;

    申请/专利号US20040796358

  • 发明设计人 MATTHEW CONOVER;

    申请日2004-03-08

  • 分类号G06F12/00;G06F13/00;G06F13/28;G06F11/00;

  • 国家 US

  • 入库时间 2022-08-21 20:09:03

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号