摘要
该文首先讨论了缓冲区漏洞的产生原理和一般攻击手段,然后分析总结Windows缓冲区溢出漏洞利用的攻击Exploit代码结构和特征,最后讨论了这些特征在入侵检测领域中的应用以及基于系统调用特征的入侵检测这一最新发展方向。
In this paper we first introduce the principle and attack methods of buffer overflow. Then analyze the structure and features of buffer overflow exploit code and summarize the characters of the code. We also discuss how to use these characters into intrusion detection systems and point out the new develop trend in intrusion detection using the system call character.
出处
《计算机安全》
2008年第1期48-49,52,共3页
Network & Computer Security
基金
国防预研基金资助项目