...
首页> 外文期刊>IEEE transactions on information forensics and security >Musti: Dynamic Prevention of Invalid Object Initialization Attacks
【24h】

Musti: Dynamic Prevention of Invalid Object Initialization Attacks

机译:Musti:动态预防无效的对象初始化攻击

获取原文
获取原文并翻译 | 示例
           

摘要

Invalid object initialization vulnerabilities have been identified since the 1990s by a research group at Princeton University. These vulnerabilities are critical since they can be used to totally compromise the security of a Java virtual machine (JVM). Recently, such a vulnerability identified as CVE-2017-3289 has been found again in the bytecode verifier of the JVM and affects more than 40 versions of the JVM. In this paper, we present a runtime solution called MUSTI to detect and prevent attacks leveraging this kind of critical vulnerabilities. We optimize MUSTI to have a runtime overhead below 0.5% and a memory overhead below 0.42%. Compared with state of the art, MUSTI is completely automated and does not require to manually annotate the code.
机译:自1990年代以来,普林斯顿大学的一个研究小组已确定了无效的对象初始化漏洞。这些漏洞非常关键,因为它们可以用来完全损害Java虚拟机(JVM)的安全性。最近,在JVM的字节码验证程序中再次发现了标识为CVE-2017-3289的漏洞,该漏洞影响JVM的40多个版本。在本文中,我们提出了一种称为MUSTI的运行时解决方案,以利用这种严重漏洞检测并防止攻击。我们优化MUSTI,使其运行时开销低于0.5%,内存开销低于0.42%。与现有技术相比,MUSTI是完全自动化的,不需要手动注释代码。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号