首页    期刊浏览 2024年12月02日 星期一
登录注册

文章基本信息

  • 标题:Unlink Attack Defense Method Based on New Chunk Structure
  • 本地全文:下载
  • 作者:Yuanzhi Huo ; Gang Wang ; Fachang Yang
  • 期刊名称:Journal of Information Security
  • 印刷版ISSN:2153-1234
  • 电子版ISSN:2153-1242
  • 出版年度:2019
  • 卷号:10
  • 期号:3
  • 页码:177-187
  • DOI:10.4236/jis.2019.103010
  • 语种:English
  • 出版社:Scientific Research Publishing
  • 摘要:The Unlink attack is a way of attacking the heap overflow vulnerability under the Linux platform. However, because the heap overflow data seldom directly leads to program control flow hijacking and related protection mechanism limitations, the existing detection technology is difficult to judge whether the program meets the heap overflow attack condition. There are certain inspection measures in the existing unlink mechanism, but with carefully constructing the contents of the heap, you can bypass the inspection measures. The unlink mechanism must be triggered with the free function, and this principle is similar to function-exit of stacks. The paper obtains the inspiration through the canary protection mechanism in the stack, adds it to the chunk structure, encrypts the canary value, and defends the unlink attack from the fundamental structure. The experimental results show that this method can effectively prevent the occurrence of unlink attacks and has the ability to detect common heap overflows.
  • 关键词:Heap Overflow;Canary;Overflow
国家哲学社会科学文献中心版权所有