The Halting Problems of Network Stack Insecurity

The Halting Problems of Network Stack Insecurity
复制标题

网络堆栈不安全的停机问题

DOI:
--
复制
发表时间:
2011
期刊:
Login: The Usenix Magazine
影响因子:
--
通讯作者:
Anna Shubina
Anna Shubina
中科院分区:
--
文献类型:
--
作者:
Len Sassaman;M. Patterson;S. Bratus;Anna Shubina

文献摘要

被引文献

相似文献

即使经过多年的共同努力,日常计算机的不安全性只会变得更糟。我们一定错过了一些基本但容易应用的见解,例如为什么有些设计不能被保护,如何避免投资和重新创建它们,以及为什么有些设计比其他设计更安全。我们认为,通过将程序和网络协议栈的有效或预期输入视为必须易于解析的输入语言,我们可以极大地提高安全性。我们认为,相反的情况也是如此:一个系统的有效或预期的输入不能简单地解析,在实践中不能安全。
Everyday computer insecurity has only gotten worse, even after many years of concerted effort. We must be missing some fundamental yet easily applicable insights into why some designs cannot be secured, how to avoid investing in them and re-creating them, and why some result in less insecurity than others. We posit that by treating valid or expected inputs to programs and network protocol stacks as input languages that must be simple to parse we can immensely improve security. We posit that the opposite is also true: a system whose valid or expected inputs cannot be simply parsed cannot in practice be made secure.