首页> 外文会议>IEEE International Conference on Communications >Hiding Your Wares: Transparently Retrofitting Memory Confidentiality into Legacy Applications
【24h】

Hiding Your Wares: Transparently Retrofitting Memory Confidentiality into Legacy Applications

机译:隐藏您的商品:透明地将内存机密性改装为遗留应用程序

获取原文

摘要

Memory scanning is a common technique used by malicious programs to read and modify the memory of other programs. Guarding programs against such exploits requires memory encryption, which is presently achievable either by (i) re-writing software to make it encrypt sensitive memory contents, or (ii) employing hardware-based solutions. These approaches are complicated, costly, and present their own vulnerabilities. In this paper, we describe new secure software technology that enables users to transparently add memory encryption to their existing software, without requiring users to invest in costly encryption hardware or requiring programmers to undertake complicated software redesign/redeployment. The Memory Encryption and Transparent Aegis Library (METAL) functions as a shim library, allowing legacy applications to transparently enjoy an assurance of memory confidentiality and integrity. The proposed solution is tunable in terms of trade-offs between security and computational overhead. We describe the design of the library and evaluate its benefits and performance trade-offs.
机译:内存扫描是恶意程序使用的常用技术,以读取和修改其他程序的内存。防范此类漏洞的程序需要内存加密,其目前可以通过(i)重新编写软件来使其加密敏感内存内容,或(ii)采用基于硬件的解决方案。这些方法复杂,昂贵,并呈现自己的漏洞。在本文中,我们描述了新的安全软件技术,使用户能够透明地将内存加密添加到其现有软件,而无需用户投资昂贵的加密硬件或要求程序员进行复杂的软件重新设计/重新部署。内存加密和透明的AEGIS库(金属)用作垫片库,允许遗留应用程序透明地享受内存机密性和完整性的保证。所提出的解决方案是在安全和计算开销之间的权衡方面进行调谐。我们描述了图书馆的设计,并评估其利益和性能权衡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号