摘要
利用格式串脆弱性进行攻击是网络攻击中新起的和危险的攻击方法。为解决格式串脆弱性问题,在研究和商业领域提出了各种各样的方案。从格式串函数堆栈布局等角度剖析了格式串脆弱性的原理;研究了利用格式串脆弱性进行任意读写等技巧;系统地分析了各种格式串脆弱性检测和预防技术的机制、特性、优点和不足。
Format string overflow attack is a new and dangerous attack method used in network attacks. Various solutions are developed to address the format string vulnerability problem in both research and commercial communities. First, format string vulnerability rationale is anatomized; then format string vulnerability exploiting technologies are researched; finally the mechanism, the characteristics, the merits and the limitations of format string vulnerability detection and prevention technology are analyzed systematically.
出处
《计算机工程与设计》
CSCD
北大核心
2006年第16期2931-2934,共4页
Computer Engineering and Design
基金
国家863高技术研究发展计划基金项目(2003AA146010)
关键词
格式串
脆弱性
格式串脆弱性
安全
C语言
format string
vulnerability
format string vulnerability
security
C language