期刊文献+

格式串脆弱性的原理、利用、检测和预防

Format string vulnerability rationale,exploiting,detection and prevention
下载PDF
导出
摘要 利用格式串脆弱性进行攻击是网络攻击中新起的和危险的攻击方法。为解决格式串脆弱性问题,在研究和商业领域提出了各种各样的方案。从格式串函数堆栈布局等角度剖析了格式串脆弱性的原理;研究了利用格式串脆弱性进行任意读写等技巧;系统地分析了各种格式串脆弱性检测和预防技术的机制、特性、优点和不足。 Format string overflow attack is a new and dangerous attack method used in network attacks. Various solutions are developed to address the format string vulnerability problem in both research and commercial communities. First, format string vulnerability rationale is anatomized; then format string vulnerability exploiting technologies are researched; finally the mechanism, the characteristics, the merits and the limitations of format string vulnerability detection and prevention technology are analyzed systematically.
出处 《计算机工程与设计》 CSCD 北大核心 2006年第16期2931-2934,共4页 Computer Engineering and Design
基金 国家863高技术研究发展计划基金项目(2003AA146010)
关键词 格式串 脆弱性 格式串脆弱性 安全 C语言 format string vulnerability format string vulnerability security C language
  • 相关文献

参考文献8

  • 1Greg Hoglund,Gary McGraw.Exploiting software how to break code[M].Boston:Addison Wesley,2004.
  • 2Scut.Exploiting format string vulnerabilities[EB/OL].2001.http://www.mindsec.com/files/formatstring-1.2.pdf.
  • 3Umesh Shankar,Kunal Talwar,Jeffrey Foster,et al.Automated detection of format-string vulnerabilities using type qualifiers[C].Washington:Proceedings of the 10th USENIX Security Symposium,USENIX Association,2001.
  • 4Vinod Ganapathyy.Automatic discovery of API-level vulnerabilities[R].Madison:University of Wisconsin,2004.
  • 5Crispin Cowan.FormatGuard:Automatic protection from printf format string vulnerabilities[C].Washington:Proceedings of the 10th USENIX Security Symposium,USENIX Association,2001.
  • 6Kyung-Suk Lhee,Steve Chapin.Buffer overflow and format string overflow vulnerabilities[J].Software-Practice and Experience,2003,33(5):423-460.
  • 7Michael Ringenburg,Dan Grossman.Preventing format-string attacks via automatic and efficient dynamic checking[EB/OL].2005.http://www.cs.washington.edu/homes/miker/format_string.pdf.
  • 8Trevor Jim.Cyclone:A safe dialect of C[C].Monterey:USENIX Annual Technical Conference,USENIX Association,2002.275-288.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部