Dynamic tracking reinforcement based on simplified control flow

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

With the rapid development of computer science and Internet technology, software security issues have become one of the main threats to information system. The technique of execution path tracking based on control flow integrity is an effective method to improve software security. However, the dynamic tracking method may incur considerable performance overhead. To address this problem, this paper proposes a method of dynamic control flow enforcement based on API invocations. Our method is based on a key observation: most control flow attackers will invoke the sensitive APIs to achieve their malicious purpose. To defeat these attacks, we first extract the normal execution path of API calls by offline analysis. Then, we utilize the offline information for run-Time enforcement. The results of the experiment showed that our method is able to detect and prevent the control flow attacks with malicious API invocations. Compared with existing methods, the system performance is improved.

源语言英语
主期刊名Proceedings - 2015 11th International Conference on Computational Intelligence and Security, CIS 2015
出版商Institute of Electrical and Electronics Engineers Inc.
358-362
页数5
ISBN(电子版)9781467386609
DOI
出版状态已出版 - 1 2月 2016
活动11th International Conference on Computational Intelligence and Security, CIS 2015 - Shenzhen, 中国
期限: 19 12月 201520 12月 2015

出版系列

姓名Proceedings - 2015 11th International Conference on Computational Intelligence and Security, CIS 2015

会议

会议11th International Conference on Computational Intelligence and Security, CIS 2015
国家/地区中国
Shenzhen
时期19/12/1520/12/15

指纹

探究 'Dynamic tracking reinforcement based on simplified control flow' 的科研主题。它们共同构成独一无二的指纹。

引用此