2010Computers & SecurityRequires access

Call-Stack Integrity based Buffer Overflow Detection Method

Zhou Yu

Open publisher page 1 citations

Abstract

Buffer overflow is one of the most threats to the system security, and a strong emphasis has been laid on the research of detection method. Call-Stack Integrity (CSI) based detection method is different from any existing detection technology. CSI performs the task of buffer overflow detection using general call-stack integrity rules, whose implementation is transparent to existing application. The test on CSI prototype system, implemented in Linux kernel, indicates that the method itself is efficient with low overhead caused and is effective to detect various buffer overflow attack, including shellcode based attack and more advanced attack, such as return into libc. Hence, the detection ability of CSI is better than other known detection methods.

About this research paper

What this paper is about

Buffer overflow is one of the most threats to the system security, and a strong emphasis has been laid on the research of detection method. Call-Stack Integrity (CSI) based detection method is different from any existing detection technology. CSI performs the task of buffer overflow detection using general call-stack integrity rules, whose implementation is transparent to existing application. The test on CSI prototype system, implemented in Linux kernel, indicates that the method itself is efficient with low overhead caused and is effective to detect various buffer overflow attack, including shellcode based attack and more advanced attack, such as return into libc. Hence, the detection ability of CSI is better than other known detection methods.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Buffer overflow is one of the most threats to the system security, and a strong emphasis has been laid on the research of detection method. Call-Stack Integrity (CSI) based detection method is different from any existing detection technology. CSI performs the task of buffer overflow detection using general call-stack integrity rules, whose implementation is transparent to existing application. The test on CSI prototype system, implemented in Linux kernel, indicates that the method itself is efficient with low overhead caused and is effective to detect various buffer overflow attack, including shellcode based attack and more advanced attack, such as return into libc. Hence, the detection ability of CSI is better than other known detection methods.

Key concepts: Buffer overflow, Computer science, System call, Overhead (engineering), Call stack, Stack (abstract data type), Kernel (algebra), Task (project management)

Related papers

Back to paper searchBrowse research topicsOriginal source
Call-Stack Integrity based Buffer Overflow Detection Method — Research Paper | ScholarLens