节点文献
基于内存更新记录的漏洞攻击错误定位方法
Automatic Fault Localization to Memory Corruption Vulnerabilities Based on Memory Update Log
【摘要】 软件漏洞攻击威胁日益严重。其中基于内存腐败漏洞的攻击最为普遍,如缓冲区溢出和格式化串漏洞。提出一种针对内存腐败漏洞攻击的自动错误定位方法。基于内存更新操作记录,可以回溯找到程序源代码中腐败关键数据的语句,从而提供有益的信息修复漏洞并生成最终补丁。
【Abstract】 Attacks exploiting vulnerabilities in software are becoming a great threat to the society.The most common attack method is to exploit memory corruption vulnerabilities such as buffer overflow and format string bugs.This paper presented a fault localization approach to automatically identify both known and unknown memory corruption vulnerabilities.Based on memory update log,we can trace back to the statement in source code that is tricked to corrupt critical data.The proposed techniques can provide useful information in fixing the vulnerabilities and generating the real patch.
【关键词】 内存腐败攻击;
软件安全;
错误定位;
【Key words】 Memory corruption attack; Software security; Fault Localization;
【Key words】 Memory corruption attack; Software security; Fault Localization;
【基金】 国家863高技术研究计划(No.2007AA01Z448);国家自然科学基金(60773171);江苏省自然科学基金(BK2007136)的资助
- 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2009年01期
- 【分类号】TP393.08
- 【被引频次】3
- 【下载频次】135