StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks

StackGuard: Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks
复制标题

DOI:
--
复制
发表时间:
1998-01
影响因子:
3.9
通讯作者:
C. Cowan
C. Cowan
中科院分区:
材料科学2区
文献类型:
--
作者:
C. Cowan

文献摘要

被引文献

相似文献

针对持续存在的缓冲区溢出攻击问题,提出了一种系统的解决方案。缓冲区溢出攻击在1988年互联网上的莫里斯蠕虫事件中臭名昭著。虽然修复单个缓冲区溢出漏洞相当简单,但缓冲区溢出攻击一直持续到今天。已经发现了数百种攻击,虽然大多数明显的漏洞现在已经被修补,但更复杂的缓冲区溢出攻击仍在继续出现。我们描述StackGuard:一种简单的编译器技术,它实际上消除了缓冲区溢出漏洞,只有适度的性能损失。使用StackGuard编译器扩展重新编译的特权程序不再将控制权交给攻击者,而是进入故障安全状态。这些程序根本不需要更改源代码,并且与现有的操作系统和库具有二进制兼容性。我们描述了编译器技术(对gcc的一个简单补丁),以及在防渗透和性能之间进行权衡的技术的一组变体。我们给出了该技术的穿透阻力和性能影响的实验结果。
This paper presents a systematic solution to the persistent problem of buffer overflow attacks. Buffer overflow attacks gained notoriety in 1988 as part of the Morris Worm incident on the Internet. While it is fairly simple to fix individual buffer overflow vulnerabilities, buffer overflow attacks continue to this day. Hundreds of attacks have been discovered, and while most of the obvious vulnerabilities have now been patched, more sophisticated buffer overflow attacks continue to emerge. We describe StackGuard: a simple compiler technique that virtually eliminates buffer overflow vulnerabilities with only modest performance penalties. Privileged programs that are recompiled with the StackGuard compiler extension no longer yield control to the attacker, but rather enter a fail-safe state. These programs require no source code changes at all, and are binary-compatible with existing operating systems and libraries. We describe the compiler technique (a simple patch to gcc), as well as a set of variations on the technique that trade-off between penetration resistance and performance. We present experimental results of both the penetration resistance and the performance impact of this technique.