【24h】

Inscription: Thwarting ActionScript Web Attacks From Within

机译:题词:从内部阻止ActionScript Web攻击

获取原文
获取原文并翻译 | 示例

摘要

The design and implementation of Inscription, the first fully automated Adobe Flash binary code transformation system that can guard major Flash vulnerability categories without modifying vulnerable Flash VMs, is presented and evaluated. Inscription affords a means of mitigating the significant class of web attacks that target unpatched, legacy Flash VMs and their apps. Such legacy VMs, and the new and legacy Flash apps that they run, continue to abound in a staggering number of web clients and hosts today; their security issues routinely star in major annual threat reports and exploit kits worldwide. Through two complementary binary transformation approaches based on in-lined reference monitoring, it is shown that many of these exploits can be thwarted by a third-party principal (e.g., web page publisher, ad network, network firewall, or web browser) lacking the ability to universally patch all end-user VMs-write-access to the untrusted Flash apps (prior to execution) suffices. Detailed case-studies describing proof-of-concept exploits and mitigations for five major vulnerability categories are reported.
机译:介绍并评估了Inscription的设计和实现,Inscription是第一个完全自动化的Adobe Flash二进制代码转换系统,它可以保护主要的Flash漏洞类别,而无需修改易受攻击的Flash VM。铭文提供了一种缓解针对未修补的旧版Flash VM及其应用程序的重要Web攻击的方法。如今,这样的旧版VM以及它们运行的​​新版和旧版Flash应用程序仍在数量惊人的Web客户端和主机中大量存在。他们的安全问题通常会在全球主要的年度威胁报告和漏洞利用工具包中脱颖而出。通过基于内联参考监视的两种互补的二进制转换方法,表明许多漏洞利用都可能受到缺乏漏洞的第三方主体(例如,网页发布者,广告网络,网络防火墙或网络浏览器)的阻碍。通用地修补所有最终用户VM到非信任Flash应用程序的写入访问权限(在执行之前)就足够了。报告了详细的案例研究,描述了五个主要漏洞类别的概念验证漏洞和缓解措施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号