TY - GEN
T1 - Efficient array & pointer bound checking against buffer overflow attacks via hardware/software
AU - Shao, Zili
AU - Xue, Chun
AU - Zhuge, Qingfeng
AU - Sha, Edwin H.-M.
AU - Xiao, Bin
PY - 2005
Y1 - 2005
N2 - Buffer overflow attacks cause serious security problems. Array & pointer bound checking is one of the most effective approaches for defending against buffer overflow attacks when source code is available. However, original array & pointer bound checking causes too much overhead since it is designed to catch memory errors and it puts too many checks. In this paper, we propose an efficient array & pointer bound checking strategy to defend against buffer overflow attacks. In our strategy, only the bounds of write operations are checked. We discuss the optimization strategy via hardware/software and conduct experiments. The experimental results show that our strategy can greatly reduce the overhead of array & pointer bound checking. Our conclusion is that based on our strategy, array & pointer bound checking can be a practical solution for defending systems against buffer overflow attacks with tolerable overhead. © 2005 IEEE.
AB - Buffer overflow attacks cause serious security problems. Array & pointer bound checking is one of the most effective approaches for defending against buffer overflow attacks when source code is available. However, original array & pointer bound checking causes too much overhead since it is designed to catch memory errors and it puts too many checks. In this paper, we propose an efficient array & pointer bound checking strategy to defend against buffer overflow attacks. In our strategy, only the bounds of write operations are checked. We discuss the optimization strategy via hardware/software and conduct experiments. The experimental results show that our strategy can greatly reduce the overhead of array & pointer bound checking. Our conclusion is that based on our strategy, array & pointer bound checking can be a practical solution for defending systems against buffer overflow attacks with tolerable overhead. © 2005 IEEE.
UR - https://www.scopus.com/pages/publications/24744464365
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-24744464365&origin=recordpage
M3 - RGC 32 - Refereed conference paper (with host publication)
SN - 769523153
VL - 1
SP - 780
EP - 785
BT - International Conference on Information Technology: Coding and Computing, ITCC
T2 - ITCC 2005 - International Conference on Information Technology: Coding and Computing
Y2 - 4 April 2005 through 6 April 2005
ER -