RPS: An Extension of Reference Monitor to Prevent Race-Attacks
RPS: An Extension of Reference Monitor to Prevent Race-Attacks
复制标题
RPS:参考监视器的扩展,以防止竞争攻击
DOI:
10.1007/978-3-540-30541-5_68
复制
发表时间:
2004
期刊:
影响因子:
--
通讯作者:
Dong
中科院分区:
文献类型:
--
作者:
Jongwoon Park;Gunhee Lee;Sangha Lee;Dong
Most software involves some vulnerabilities because of various potential factors such as design flaw and program bug. Among them, a faulty assumption on file access results in a side-effect as known TOCTTOU vulnerability. Race–attack is an attack using this vunerability. In this paper, we propose a novel mechanism to prevent race–attack, each process maintains status of related object at check step operation and compares the status of the use step with that of the check step. Since every process must pass through the reference monitor to use an object, it is the most suitable point to detect the attack and response to the attack.