...
首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >A Taxonomy of Buffer Overflow Characteristics
【24h】

A Taxonomy of Buffer Overflow Characteristics

机译:缓冲区溢出特征分类

获取原文
获取原文并翻译 | 示例
           

摘要

Significant work on vulnerabilities focuses on buffer overflows, in which data exceeding the bounds of an array is loaded into the array. The loading continues past the array boundary, causing variables and state information located adjacent to the array to change. As the process is not programmed to check for these additional changes, the process acts incorrectly. The incorrect action often places the system in a nonsecure state. This work develops a taxonomy of buffer overflow vulnerabilities based upon characteristics, or preconditions that must hold for an exploitable buffer overflow to exist. We analyze several software and hardware countermeasures to validate the approach. We then discuss alternate approaches to ameliorating this vulnerability.
机译:有关漏洞的重要工作集中在缓冲区溢出上,在缓冲区溢出中,将超出数组范围的数据加载到数组中。加载继续超过数组边界,导致与数组相邻的变量和状态信息发生变化。由于未对该过程进行编程以检查这些其他更改,因此该过程无法正确执行。错误的操作通常会使系统处于非安全状态。这项工作基于特征或存在可利用的缓冲区溢出所必须具备的前提条件,开发了缓冲区溢出漏洞的分类法。我们分析了几种软件和硬件对策以验证该方法。然后,我们讨论改善此漏洞的替代方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号