DocumentCode :
2682974
Title :
Multi-variant Program Execution: Using Multi-core Systems to Defuse Buffer-Overflow Vulnerabilities
Author :
Salamat, Babak ; Gal, Andreas ; Jackson, Todd ; Manivannan, Karthikeyan ; Wagner, Gregor ; Franz, Michael
Author_Institution :
Dept. of Comput. Sci., Univ. of California, Irvine, CA
fYear :
2008
fDate :
4-7 March 2008
Firstpage :
843
Lastpage :
848
Abstract :
While memory-safe and type-safe languages have been available for many years, the vast majority of software is still implemented in type-unsafe languages such as C/C++. Despite massive concerted efforts by software vendors such as Microsoft to eliminate buffer overflow vulnerabilities through automated and manual code review, they continue to be found and exploited. We present a novel approach that accepts the existence of overflow vulnerabilities and uses parallelism available through current and future multi-core architectures to detect vulnerabilities by monitoring the parallel execution of several slightly varying instances of the same application. During regular execution each instance performs equivalent computations. When an attacker attempts to inject an attack vector through a buffer overflow vulnerability, however, each instance reacts differently due to the variances we introduced into each instance. We describe our prototype implementation of such a parallelism-based buffer overflow detection system and demonstrate that it is capable of stopping buffer overflow vulnerabilities using actual exploit codes for the popular Apache Web server. The experimental results show that the runtime overhead of our parallel execution framework is less than 10% on average.
Keywords :
parallel processing; security of data; storage management; Apache Web server; attack vector; buffer-overflow vulnerability; multicore system; multivariant program execution; parallel execution; parallelism; Buffer overflow; Competitive intelligence; Computer science; Computer worms; Hardware; Microprocessors; Monitoring; Parallel processing; Prototypes; Software systems; Multi-core Processor; Multi-variant execution; buffer-overflow; variant; vulnerability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Complex, Intelligent and Software Intensive Systems, 2008. CISIS 2008. International Conference on
Conference_Location :
Barcelona
Print_ISBN :
978-0-7695-3109-0
Type :
conf
DOI :
10.1109/CISIS.2008.136
Filename :
4606777
Link To Document :
بازگشت