• DocumentCode
    259993
  • Title

    Protection against Buffer Overflow Attacks through Runtime Memory Layout Randomization

  • Author

    Kumar, K. Shiva ; Kisore, N. Raghu

  • Author_Institution
    Sch. of Comput. & Inf. Sci., Univ. of Hyderabad, Hyderabad, India
  • fYear
    2014
  • fDate
    22-24 Dec. 2014
  • Firstpage
    184
  • Lastpage
    189
  • Abstract
    To date a number of comprehensive techniques have been proposed to defend against buffer over attacks. In spite of continuing research in this area, security vulnerabilities in software continue to be discovered and exploited. This is because the existing protection techniques suffer from one or more of the following problems: high run time overheads (often exceeding 100%), incompatibility with legacy C and C++ code, not sufficiently fine grained randomization of memory layout and the inability to perform randomization at run time rather than compile time or link time or load time. While security through diversity is a promising technique to defend against large scale cyber attacks, existing techniques are susceptible to information leakage and brute-force attacks, in addition to the short comings indicated above. To overcome the above indicated drawbacks, in this paper we propose Function Frame Run time Randomization (FFRR) technique. FFRR offers memory layout randomization at run time and performs randomization at the level of individual variables on the stack.
  • Keywords
    security of data; FFRR technique; brute-force attacks; buffer overflow attacks; cyber attacks; function frame run time randomization technique; information leakage; runtime memory layout randomization; Generators; Hardware; Internet; Layout; Libraries; Security; Software; large scale cyber-attack; memory randomization; program stack;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology (ICIT), 2014 International Conference on
  • Conference_Location
    Bhubaneswar
  • Print_ISBN
    978-1-4799-8083-3
  • Type

    conf

  • DOI
    10.1109/ICIT.2014.57
  • Filename
    7033319