欢迎访问中国科学院大学学报,今天是
论文

一种防止堆缓冲区溢出的新方法

  • 邱晓鹏 ,
  • 张玉清 ,
  • 冯登国
展开
  • 1. 信息安全国家重点实验室(中国科学院研究生院);
    2. 中国科学院研究生院国家计算机网络入侵防范中心, 北京 100049

收稿日期: 2004-06-04

  修回日期: 2004-07-20

  网络出版日期: 2005-03-15

基金资助

北京市科技计划项目(H020120090530)资助

A New Method to Prevent Heap Overflows

  • QIU Xiao-Peng ,
  • ZHANG Yu-Qing ,
  • FENG Deng-Guo
Expand
  • 1. State Key Laboratory of Information Security (Graduate School of the Chinese Academy of Sciences), Beijing 100049, China;
    2. National Computer Network Intrusion Protection Center, Graduate School of the Chinese Academy of Sciences, Beijing 100049, China

Received date: 2004-06-04

  Revised date: 2004-07-20

  Online published: 2005-03-15

摘要

缓冲区溢出是当今计算机安全所面临的重大威胁.首先分析了堆缓冲区溢出的原理,然后提出了一种新的内存管理机制,这种机制可以根据缓冲区的大小,自我进行内存管理,从而有效地防止堆缓冲区溢出的发生.

本文引用格式

邱晓鹏 , 张玉清 , 冯登国 . 一种防止堆缓冲区溢出的新方法[J]. 中国科学院大学学报, 2005 , 22(2) : 218 -225 . DOI: 10.7523/j.issn.2095-6134.2005.2.015

Abstract

Buffer overflows are the most serious threat to the computer security. In this paper, the principle of the heap overflows is discussed, and a method of memory management is proposed, which can perform self management to the memory. With this method, the heap overflows can be prevented effectively.

参考文献

[1] National Institut e of Standards and Technology. ICAT Metabase. http:PPicat. nist. govP

[2] SANS Inst itute. The tw enty most critical internet security vulnerabilit ies. ht tp:PPwww. sans. orgPtop20P

[3] Cowan C, Wagle P, Pu C, et al. Buffer overflows: attacks and defenses for the vulnerability of the decade. DARPA information survivabilityconference and exposition. DISCEX. 00. Proceedings, 2000, 2: 119~ 129

[4] Conover M. w00w00 Security Team, w00w00 on heap overflows. http:PPwww. w00w00. orgPf ilesParticlesPheaptut. txt

[5] Aleph One. Smashing the stack for fun and profit. Phrack, 1996, 7( 49) ht tp:PPwww. phrack. orgPshow. php? p= 49&a= 14

[6] Wilander J. Security intrusions and intrusion prevention: [Mast er thesis]. Sweden: Linkê pings Universitet,Department of Computer and Informat ionScience. www. ida. liu. seP~ johw iP

[7] Zhang XM. Sel-f manage data buff er memory-deliver code eff iciency, simplicity, portability, and security. http:PPwww-106. ibm. comPdeveloperworksPwebPlibraryPwa-memmng

[8] Robert O. Calife: how to become root w ith one. s own password. http:PPmut t. frmug. orgPcalifeP

[9] National Institut e of Standards and Technology. ICAT Metabase. http:PPicat. nist. govPicat. cfm?cvename= CAN-2004-0188

[10] McGraw G, Viega J. Make your software behave: preventing buffer overflows.http:PPwww900.ibm.comPdeveloperWorksPcnPsecurityPbufferdefendPindexeng. shtml

文章导航

/