期刊文献+

地址空间随机化技术研究

RESEARCH ON ADDRESS SPACE RANDOMIZATION TECHNIQUES
下载PDF
导出
摘要 地址空间随机化ASR(address space randomization)技术的目的是使进程空间不可预测,从而保护系统不受攻击。研究了几乎所有主流的ASR系统和技术的原理;分析了其优缺点;研究了对部分ASR系统进行攻击的方法;最后提出了实现实用的ASR系统需要注意的一些问题。 The goal of Address Space Randomization technology is to make the address space of a process unpredictable, and protect the system from attacks. Almost all main Address Space Randomization systems and technologies are studied, their advantages and shortcomings are analyzed as well, the way of attacking against some of these systems are studied, and several issues on the realization of ASR are presented in the end of the paper.
出处 《计算机应用与软件》 CSCD 2009年第9期38-41,共4页 Computer Applications and Software
基金 国家863高技术研究发展计划基金项目(2006AA01Z431)
关键词 地址空间随机化 缓冲区溢出 安全漏洞 网络安全 Address space randomization(ASR) Buffer overflow Vulnerability Network security
  • 相关文献

参考文献23

  • 1Aleph One. Smashing the stack for fun and profit[ J/OL]. Phrack Magazine, 1996,7 (49).
  • 2Michel Kaempf. Vudo malloc tricks[ J/OL]. Phrack Magazine,2001, 11(57).
  • 3Snort(tin) advisory. Integer overflow in stream4[ EB/OL] .2003 -04. http ://www. kb. cert. org/vuls/id/JPLA-5LPR9S.
  • 4Scut. Exploting format string vulnerabilities [ EB/OL]. 2001 -03. http ://www. teamteso. net/articles/formatstring.
  • 5Anonymous. Once upon a free ( ) [ J/OL ]. Phrack Magazine, 2001,9 (57).
  • 6Nergal. The advanced return-into-lib(c) exploits[ J/OL]. Phrack Magazine ,2001,11 ( 58 ).
  • 7Cowan C, Pu C, Maier D. et al. StackGuard : Automatic adaptive detection and prevention of buffer-overflow attacks [ C ]//In USENIX Security Symposium, San Antonio, Texas, 1998:63 - 78.
  • 8Cowan C, Barringer M, Beattie S, et al. FormatGuard : Automatic protection from prinff format string vulnerabilities[ C ]//In USENIX Security Symposium, Washington, DC, 2001.
  • 9PaX Team. PaX [ EB/OL]. 2001. http ://pax. grsecurity. net.
  • 10Forrest S, Somayaji A, Ackley D H. Building diverse computer systems [C]//In 6th Workshop on Hot Topics in Operating Systems, Los Alamitos, IEEE Computer Society. 1997:67 - 72.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部