Securing Software by Enforcing Data-flow Integrity 论文

2006引用 322
Security and Verification in ComputingAdvanced Malware Detection TechniquesNetwork Security and Intrusion Detection

详细信息

发表日期
2006-01-01
发表年份
2006

关键词

Security and Verification in ComputingAdvanced Malware Detection TechniquesNetwork Security and Intrusion Detection

摘要

Software attacks often subvert the intended data-flow in a vulnerable program. For example, attackers exploit buffer overflows and format string vulnerabilities to write data to unintended locations. We present a simple technique that prevents these attacks by enforcing data-flow integrity. It computes a data-flow graph using static analysis, and it instruments the program to ensure that the flow of data at runtime is allowed by the data-flow graph. We describe an efficient implementation of data-flow integrity enforcement that uses static analysis to reduce instrumentation overhead. This implementation can be used in practice to detect a broad class of attacks and errors because it can be applied automatically to C and C++ programs without modifications, it does not have false positives, and it has low overhead. 1

作者

暂无数据

相关事件

暂无数据

相关文章

暂无数据