DocumentCode :
3740241
Title :
Dynamic Tracking Reinforcement Based on Simplified Control Flow
Author :
Jiani Li;Donghai Tian;Changzhen Hu
Author_Institution :
Beijing Key Lab. of Software Security Eng. Tech., Beijing Inst. of Technol., Beijing, China
fYear :
2015
Firstpage :
358
Lastpage :
362
Abstract :
With the rapid development of computer science and Internet technology, software security issues have become one of the main threats to information system. The technique of execution path tracking based on control flow integrity is an effective method to improve software security. However, the dynamic tracking method may incur considerable performance overhead. To address this problem, this paper proposes a method of dynamic control flow enforcement based on API invocations. Our method is based on a key observation: most control flow attackers will invoke the sensitive APIs to achieve their malicious purpose. To defeat these attacks, we first extract the normal execution path of API calls by offline analysis. Then, we utilize the offline information for run-time enforcement. The results of the experiment showed that our method is able to detect and prevent the control flow attacks with malicious API invocations. Compared with existing methods, the system performance is improved.
Keywords :
"Yttrium","Security","Software","Instruments","Registers","Heuristic algorithms","Algorithm design and analysis"
Publisher :
ieee
Conference_Titel :
Computational Intelligence and Security (CIS), 2015 11th International Conference on
Type :
conf
DOI :
10.1109/CIS.2015.93
Filename :
7397107
Link To Document :
بازگشت