天堂国产午夜亚洲专区-少妇人妻综合久久蜜臀-国产成人户外露出视频在线-国产91传媒一区二区三区

當(dāng)前位置:主頁 > 科技論文 > 軟件論文 >

基于Canary復(fù)用的SSP安全缺陷分析

發(fā)布時間:2018-03-07 05:36

  本文選題:棧保護(hù)機制 切入點:Canary復(fù)用 出處:《北京郵電大學(xué)學(xué)報》2017年S1期  論文類型:期刊論文


【摘要】:核保護(hù)機制(SSP)是緩解棧緩沖區(qū)溢出漏洞攻擊最有效的安全機制,通過系統(tǒng)生成的隨機數(shù)保證棧不被修改,目前關(guān)于SSP機制的繞過技術(shù)主要是基于暴力破解.為此,揭示了一種可以泄露隨機數(shù)的安全缺陷模型,由于操作系統(tǒng)沒有及時清空死亡棧幀,導(dǎo)致隨機數(shù)可能存在于無效空間,利用此特性的繞過方式被稱為Canary復(fù)用.實驗驗證了這種安全缺陷的可利用性與穩(wěn)定性,基于此特點,提出了兩種有效的解決方案.
[Abstract]:The nuclear protection mechanism (SSP) is the most effective security mechanism to mitigate the stack buffer overflow vulnerability attack. The random number generated by the system ensures that the stack will not be modified. At present, the bypass technology of the SSP mechanism is mainly based on brute force cracking. This paper presents a security defect model that can leak random numbers. Because the operating system does not clear the dead stack frames in time, the random numbers may exist in invalid space. The bypass method using this property is called Canary reuse. The availability and stability of this security defect are verified by experiments. Based on this characteristic, two effective solutions are proposed.
【作者單位】: 江南計算技術(shù)研究所;
【分類號】:TP309


本文編號:1578179

資料下載
論文發(fā)表

本文鏈接:http://sikaile.net/kejilunwen/ruanjiangongchenglunwen/1578179.html


Copyright(c)文論論文網(wǎng)All Rights Reserved | 網(wǎng)站地圖 |

版權(quán)申明:資料由用戶c4a60***提供,本站僅收錄摘要或目錄,作者需要刪除請E-mail郵箱bigeng88@qq.com