摘要
内存溢出漏洞及其利用对计算机和网络安全构成了极大威胁。逐一分析Windows系统对栈、堆防护机制、数据执行保护和地址随机加载机制的设计和实现,测试了Windows Vista环境下绕过这些防护机制方法的可能性,指出无安全编译的软件使用已成为系统安全的短板;最后讨论了更全面提高系统安全性的改进方案。
Memory corruption vulnerabilities and exploitations have threaten the computer systerm and network sercurity very seriously. The search analysed the design and implementation of the memory protections in Windows, such as GS, SafeSEH, DEP, and ASLR. Then the testing of bypassing the protection mechanisms in Windows Vista pointed out the danger of using no_safe_compiled software. At last several measures were introduced to improve system security more complehensively.
出处
《计算机安全》
2009年第7期1-3,10,共4页
Network & Computer Security
基金
国家863基金资助项目2003AA146010