Defcon Capture the Flag: defending vulnerable code from intense attack

Defcon Capture the Flag: defending vulnerable code from intense attack
复制标题

Defcon 夺旗:保护易受攻击的代码免受强烈攻击

DOI:
--
复制
发表时间:
2003
期刊:
Proceedings DARPA Information Survivability Conference and Exposition
影响因子:
--
通讯作者:
Crispin Cowan
Crispin Cowan
中科院分区:
--
文献类型:
--
作者:
Crispin Cowan

文献摘要

被引文献

相似文献

implix/spl trade/是一个Linux系统,它使用了几种DARPA资助的安全技术,以产生一个高度可生存的服务器设备平台。Imperix技术包括:StackGuard、RaceGuard、SubDomain和LSM(Linux安全模块)。这些技术结合起来,使得攻击者很难闯入Imperix服务器,尽管存在未修补的漏洞,同时也保持了与标准Linux系统的高度兼容性。Defcon Capture-the-Flag(CtF)是最大的开放式安全黑客游戏。2002年的游戏旨在通过强迫玩家托管已知易受攻击的软件,使防御者特别难以保护他们的服务器。我们的DISCEX III论文描述了我们在这款游戏中使用Imperix服务器的经历:我们排名第二,没有人能够控制Imperix服务器。
Immunix/spl trade/ is a Linux system hardened with several DARPA-funded security technologies to produce a highly survivable server appliance platform. The Immunix technologies include: StackGuard, FormatGuard, RaceGuard, SubDomain, and LSM (Linux Security Modules). Combined, these technologies make it very difficult for an attacker to break into an Immunix server, despite the presence of unpatched vulnerabilities, while also preserving a high degree of compatibility with standard Linux systems. The Defcon Capture-the-Flag (CtF) contest is the largest open security hacking game. The 2002 game was designed to make it particularly difficult for defenders to defend their servers by forcing players to host software known to be vulnerable. Our DISCEX III paper describes our experience playing an Immunix server in this game: we placed second overall, and no one was able to take control of the Immunix server.