期刊文献+

计算机缓冲区溢出攻击问题的研究

下载PDF
导出
摘要 缓冲区溢出攻击对于因特网的攻击者来说是一个有力的工具,他们可以用它来躲避基于签名的侵入检测/预防系统。它会破坏我们重要的基础设施,比如DNS或更新服务器。本文首先介绍了C程序的存储空间布局,然后具体说明缓冲区溢出攻击的原理、攻击类型和方法,最后,提出了对应的防范策略。
作者 刘蕊
出处 《工程地质计算机应用》 2007年第4期32-35,26,共5页 Engineering Geology Computer Application
  • 相关文献

参考文献4

  • 1詹川,卢显良,袁连海.缓冲区溢出攻击及防御[J].计算机科学,2004,31(12):58-60. 被引量:2
  • 2Larochelle D,Evans D.Statically detecting likely buffer overflow vulnerabilities[].Procof theUSENIX Security Symposium.2001
  • 3A.Pasupulati,J.Coit,K.Leviu,S.F.Wu,S.H.Li,J.C.Ku0,K.P.Fan.Buttercup:On Network-based Detection of Polymorphic Buffer Overflow Vulnerabilities[]..
  • 4.Polymorphic Shellcodes vs.Application IDSs[].NGSEC White Paper.

二级参考文献18

  • 1http://www. cert. org/stats/cert-stats. html
  • 2Wagner D,Foster J S,Brewer E A,Aiken A. A first step towards automated detection of buffer overrun vulnerabilities. In:Proc. of Network and Distributed System Security Symposium, Catamaran Resort Hotel, San Diego, California, Feb. 20003.3~ 17
  • 3Spaford E. The Interner Worm Program : Analysis Computer Communication Review, Jan. 1989.3-17
  • 4DilDog. The tao of Windows buffer overflow. http://www. cultdeadcow. com/cDc-files/cDc-351/, April 1998
  • 5Conover C, w00w00 Security Team. w00w00 on heap overflows.http://www. w00w00. org/files/articles/heaptut. txt, Jan. 1999
  • 6Cowan C, et al. StackGuard: Automatic adaptive detection and prevention of buffer overflow attacks. In :Proc. of the 7th USENIX Security Conf. San Antonio, Texas, Jan. 1998.63-78
  • 7Vendicator. Stack Shield technical info file v0. 7 http://www. angelfire. com/sk/stackshiedl/, Jan. 2001
  • 8Baratloo A,Singh N ,Tsai T. Libsafe: Protecting critical elements of stacks. White paper http://www. research. avayalabs. com/project/libsafe/, Dec. 1999
  • 9Fetzer C,Xiao Z. Detecting heap smashing attacks through fault containment wrappers. In:the Proc. of the 20th symposium on Reliable Distributed Systems, Oct. 2001
  • 10Viega J,Bloch J T, et al. ITS4:A static vlnerability scanner for C and C++ code. In: Proc. of the 16th Annual Computer Security Applications Conf. Dec. 2000

共引文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部