A programming learning environment "azur": Visualizing block structures and program function behavior

A programming learning environment "azur": Visualizing block structures and program function behavior
复制标题

编程学习环境“azur”:可视化块结构和程序函数行为

DOI:
10.1145/1542476.1542505
复制
发表时间:
2010
影响因子:
46.2
通讯作者:
S. Komiya
S. Komiya
中科院分区:
化学1区
文献类型:
--
作者:
T. Imaizumi;Hiroaki Hashiura;Saeko Matsuura;S. Komiya

文献摘要

被引文献

相似文献

本文描述了一个完全内存安全的 C 语言程序编译器,它与 ANSI C 规范完全兼容。用 C 编写的程序经常会因悬空指针和缓冲区溢出而遭受严重错误。 Internet 服务器程序中的此类错误经常被恶意攻击者利用来破解整个系统。这些错误的根源通常是由越界数组访问引起的内存数据结构损坏。通常的 C 编译器不提供任何针对此类越界访问的保护,尽管许多其他语言(例如 Java 和 ML)确实提供了此类保护。已经有一些建议从各个方面防止此类内存损坏:运行时缓冲区溢出检测器、新的类 C 语言的设计以及 C 语言(子集)的编译器。然而,据我们所知,它们都没有同时实现完全的内存保护和与C语言规范的完全兼容。我们针对这个问题提出了有史以来最强大的解决方案。我们开发了Fail-Safe C,这是完整 ANSI C 语言的内存安全实现。它检测并禁止所有不安全操作,但符合完整的 ANSI C 标准(包括强制转换和联合)。本文介绍了几种技术(编译时和运行时)来减少运行时检查的开销,同时仍然保持 100% 的内存安全。该编译器使程序员可以轻松地确保程序安全,而无需大量重写或移植代码。它还支持许多现有 C 程序中常用的许多“肮脏技巧”,这些技巧并不严格符合标准规范。在本文中,我们演示了几个可以由我们的编译器处理的实际服务器程序,并介绍了它的技术细节和基准测试结果。
This paper describes a completely memory-safe compiler for C language programs that is fully compatible with the ANSI C specification.Programs written in C often suffer from nasty errors due to dangling pointers and buffer overflow. Such errors in Internet server programs are often exploited by malicious attackers to crack an entire system. The origin of these errors is usually corruption of in-memory data structures caused by out-of-bound array accesses. Usual C compilers do not provide any protection against such out-of-bound access, although many other languages such as Java and ML do provide such protection. There have been several proposals for preventing such memory corruption from various aspects: runtime buffer overrun detectors, designs for new C-like languages, and compilers for (subsets of) the C language. However, as far as we know, none of them have achieved full memory protection and full compatibility with the C language specification at the same time.We propose the most powerful solution to this problem ever presented. We have developedFail-Safe C, a memory-safe implementation of the full ANSI C language. It detects and disallows all unsafe operations, yet conforms to the full ANSI C standard (including casts and unions). This paper introduces several techniques--both compile-time and runtime--to reduce the overhead of runtime checks, while still maintaining 100% memory safety. This compiler lets programmers easily make their programs safe without heavy rewriting or porting of their code. It also supports many of the "dirty tricks" commonly used in many existing C programs, which do not strictly conform to the standard specification. In this paper, we demonstrate several real-world server programs that can be processed by our compiler and present technical details and benchmark results for it.