• DocumentCode
    2682974
  • Title

    Multi-variant Program Execution: Using Multi-core Systems to Defuse Buffer-Overflow Vulnerabilities

  • Author

    Salamat, Babak ; Gal, Andreas ; Jackson, Todd ; Manivannan, Karthikeyan ; Wagner, Gregor ; Franz, Michael

  • Author_Institution
    Dept. of Comput. Sci., Univ. of California, Irvine, CA
  • fYear
    2008
  • fDate
    4-7 March 2008
  • Firstpage
    843
  • Lastpage
    848
  • Abstract
    While memory-safe and type-safe languages have been available for many years, the vast majority of software is still implemented in type-unsafe languages such as C/C++. Despite massive concerted efforts by software vendors such as Microsoft to eliminate buffer overflow vulnerabilities through automated and manual code review, they continue to be found and exploited. We present a novel approach that accepts the existence of overflow vulnerabilities and uses parallelism available through current and future multi-core architectures to detect vulnerabilities by monitoring the parallel execution of several slightly varying instances of the same application. During regular execution each instance performs equivalent computations. When an attacker attempts to inject an attack vector through a buffer overflow vulnerability, however, each instance reacts differently due to the variances we introduced into each instance. We describe our prototype implementation of such a parallelism-based buffer overflow detection system and demonstrate that it is capable of stopping buffer overflow vulnerabilities using actual exploit codes for the popular Apache Web server. The experimental results show that the runtime overhead of our parallel execution framework is less than 10% on average.
  • Keywords
    parallel processing; security of data; storage management; Apache Web server; attack vector; buffer-overflow vulnerability; multicore system; multivariant program execution; parallel execution; parallelism; Buffer overflow; Competitive intelligence; Computer science; Computer worms; Hardware; Microprocessors; Monitoring; Parallel processing; Prototypes; Software systems; Multi-core Processor; Multi-variant execution; buffer-overflow; variant; vulnerability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Complex, Intelligent and Software Intensive Systems, 2008. CISIS 2008. International Conference on
  • Conference_Location
    Barcelona
  • Print_ISBN
    978-0-7695-3109-0
  • Type

    conf

  • DOI
    10.1109/CISIS.2008.136
  • Filename
    4606777