中大學術數位典藏-NCU Institutional Repository:Item 987654321/106332
English  |  正體中文  |  简体中文  |  全文笔数/总笔数 : 94459/94459 (100%)
造访人次 : 87654163      在线人数 : 243
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
搜寻范围 查询小技巧:
  • 您可在西文检索词汇前后加上"双引号",以获取较精准的检索结果
  • 若欲以作者姓名搜寻,建议至进阶搜寻限定作者字段,可获得较完整数据
  • 进阶搜寻


    jsp.display-item.identifier=請使用永久網址來引用或連結此文件: https://ir.lib.ncu.edu.tw/handle/987654321/106332


    题名: ARMORY: An automatic security testing tool for buffer overflow defect detection
    作者: 蘇木春;Chen, Li-Han;Hsu, Fu-Hau;Hwang, Yanling;Su, Mu-Chun;Ku, Wei-Shinn;Chang, Chi-Hsuan
    贡献者: 資訊電機學院資訊工程學系
    关键词: Buffers;Computer information security;Computer programs;Defects;Finishes;Software;Source code
    日期: 2013-10-01
    上传时间: 2026-04-23 13:17:59 (UTC+8)
    出版者: Elsevier Ltd.;Elsevier Ltd
    摘要: 摘要: [Display omitted] ► ARMORY detects buffer overflow defects automatically inside kernel. ► It classifies three types of buffer overflow defects: L2S, LOOP, and FISSION. ► It does not need any attack instance, any training phase, and source code. Program Buffer Overflow Defects (PBODs) are the stepping stones of Buffer Overflow Attacks (BOAs), which are one of the most dangerous security threats to the Internet. In this paper, we propose a kernel-based security testing tool, named ARMORY, for software engineers to detect PBODs automatically when they apply all kinds of testing, especially functional testing and unit testing, without increasing the testing workload. Besides, ARMORY does not need any attack instance, any training phase, or source code to finish its security testing. ARMORY can detect unknown PBODs. ARMORY not only can improve software quality, but also can reduce the amount of system resources used to protect a system. We implemented ARMORY in Linux kernel by modifying sys_read() system call and entry. S which deals all system call. Experimental results show that ARMORY can automatically detect PBODs when programmers test the functionality of their programs.
    出版者: Elsevier Ltd
    出版日期: 2013-10-01
    出處: Computers & electrical engineering, 2013-10, Vol.39 (7), p.2233-2242
    版權: 2012 Elsevier Ltd
    識別號: ISSN: 0045-7906
    識別號: EISSN: 1879-0755
    識別號: DOI: 10.1016/j.compeleceng.2012.07.005
    显示于类别:[資訊工程學系] 期刊論文

    文件中的档案:

    档案 描述 大小格式浏览次数
    index.html0KbHTML26检视/开启


    在NCUIR中所有的数据项都受到原著作权保护.

    社群 sharing

    ::: Copyright National Central University. | 國立中央大學圖書館版權所有 | 收藏本站 | 設為首頁 | 最佳瀏覽畫面: 1024*768 | 建站日期:8-24-2009 :::
    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - 隱私權政策聲明