期刊文献+

堆溢出的攻击演变与防范

Heap Overflows:Evolution of Attacks and Defenses
下载PDF
导出
摘要 以栈溢出为主的缓冲区溢出研究取得了较为丰硕的成果,与其相比,堆溢出攻击要困难许多,研究力度也少了许多。然而我们绝不能低估基于堆的溢出攻击,事实上,堆溢出已经成为攻击软件的主要方式之一。论文从基本的堆溢出开始,详细研究了堆溢出的主要攻击手段及其演变,介绍了各种常见的防御措施,并且对这些研究成果进行了分析总结。最后陈述了我们对此问题的观点。 Heap overflows are more difficult to exploit than stack based overilows,and researches on it seem a Pit fewer comparing to the latter.However,we cannot underestimate the severity heap-based overflow attacks bring to computer systems,and in fact,heap overflow attacks have become one of the main methods compromising the software security.Commencing from the basic heap overflow attacks,this paper surveys all kinds of heap overflows vulnerabilities, most commonly used attacks and their evolutions.Various defense methods as well as summarizations to them are also narrated.Finally,we present our point of view on heap overflows.
出处 《计算机工程与应用》 CSCD 北大核心 2006年第25期102-107,119,共7页 Computer Engineering and Applications
基金 国家863高技术研究发展计划资助项目(编号:2003AA144010)
关键词 堆溢出 缓冲区溢出 攻击 防范 计算机安全 heap overflow, buffer overflow, attacks, defense, computer security
  • 相关文献

参考文献22

  • 1Executable and Linkable Format(ELF)[S].Portable Formats Specification,Version 1.1
  • 2M Conover,w00w00 Security Team.w00w00 on heap overflows.http://www.w00w00.org/files/articles/heaptut.txt,1999-01
  • 3James C Foster,Vitaly Osipov,Nish Bhalla et al.Buffer Overflow Attacks:Detect,Exploit,Prevent[M].Syngress Publishing,Inc,2005
  • 4P A Fayolle,V Glaume.A Buffer Overflow Study Attacks & Defenses.ENSEIRB,Networks and Distributed Systems,2002
  • 5Jonathan Pincus,Brandon Baker.Beyond Stack Smashing:Recent Advances in Exploiting Buffer Overruns[J].IEEE SECURITY & PRIVACY,2004-07/08
  • 6Anonymous.Once upon a free().Phrack,57,2001
  • 7Solar Designer.JPEG COM Marker Processing Vulnerability in Netscape Browsers.http://www.openwall.com/advisories/OW-002-netscapejpeg.txt
  • 8BBP.BSD heap smashing.http://bbp.krukh.net/blabla/BSD-heap-smashing.txt,2003-05
  • 9Michel Kaempf.Vudo-an object superstitiously believed to embody magical powers.Phrack,57,2001
  • 10rix.Smashing C++ vptrs.Phrack Magazine 56,http://www.phrack.org/phrack/56/p56-0x08,2000-05

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部