Welcome to Journal of University of Chinese Academy of Sciences,Today is

A New Method to Prevent Heap Overflows

  • QIU Xiao-Peng ,
  • ZHANG Yu-Qing ,
  • FENG Deng-Guo
Expand
  • 1. State Key Laboratory of Information Security (Graduate School of the Chinese Academy of Sciences), Beijing 100049, China;
    2. National Computer Network Intrusion Protection Center, Graduate School of the Chinese Academy of Sciences, Beijing 100049, China

Received date: 2004-06-04

  Revised date: 2004-07-20

  Online published: 2005-03-15

Abstract

Buffer overflows are the most serious threat to the computer security. In this paper, the principle of the heap overflows is discussed, and a method of memory management is proposed, which can perform self management to the memory. With this method, the heap overflows can be prevented effectively.

Cite this article

QIU Xiao-Peng , ZHANG Yu-Qing , FENG Deng-Guo . A New Method to Prevent Heap Overflows[J]. Journal of University of Chinese Academy of Sciences, 2005 , 22(2) : 218 -225 . DOI: 10.7523/j.issn.2095-6134.2005.2.015

References

[1] National Institut e of Standards and Technology. ICAT Metabase. http:PPicat. nist. govP

[2] SANS Inst itute. The tw enty most critical internet security vulnerabilit ies. ht tp:PPwww. sans. orgPtop20P

[3] Cowan C, Wagle P, Pu C, et al. Buffer overflows: attacks and defenses for the vulnerability of the decade. DARPA information survivabilityconference and exposition. DISCEX. 00. Proceedings, 2000, 2: 119~ 129

[4] Conover M. w00w00 Security Team, w00w00 on heap overflows. http:PPwww. w00w00. orgPf ilesParticlesPheaptut. txt

[5] Aleph One. Smashing the stack for fun and profit. Phrack, 1996, 7( 49) ht tp:PPwww. phrack. orgPshow. php? p= 49&a= 14

[6] Wilander J. Security intrusions and intrusion prevention: [Mast er thesis]. Sweden: Linkê pings Universitet,Department of Computer and Informat ionScience. www. ida. liu. seP~ johw iP

[7] Zhang XM. Sel-f manage data buff er memory-deliver code eff iciency, simplicity, portability, and security. http:PPwww-106. ibm. comPdeveloperworksPwebPlibraryPwa-memmng

[8] Robert O. Calife: how to become root w ith one. s own password. http:PPmut t. frmug. orgPcalifeP

[9] National Institut e of Standards and Technology. ICAT Metabase. http:PPicat. nist. govPicat. cfm?cvename= CAN-2004-0188

[10] McGraw G, Viega J. Make your software behave: preventing buffer overflows.http:PPwww900.ibm.comPdeveloperWorksPcnPsecurityPbufferdefendPindexeng. shtml

Outlines

/