DocumentCode
618381
Title
Automated diagnosis and prevention of unsafe dynamic software component loadings
Author
Balakrishnan, Ranjith ; Anbarasu, J.
Author_Institution
Dept. of Tifac-Core in Pervasive Comput. Technol., Velammal Eng. Coll., Chennai, India
fYear
2013
fDate
11-12 April 2013
Firstpage
739
Lastpage
743
Abstract
For an improved system modularity and flexibility through code reuse, efficient memory usage, and reduced disk space dynamic loading of software components is widely used mechanism in operating system. However, Programming mistakes may create malicious components being loaded with regular dynamic loadings. In particular, dynamic loadings can be made as malicious components by placing an arbitrary file with the same or specified name in target components. Although this issue has not been considered serious because such vulnerabilities are dangerous than virus and exploiting it requires access to local file system. This kind of malicious will act as original dynamic loadings with the same name and makes remote exploitation realistic. To avoid remote attacks and intruders, in this paper we present the automated technique to detect unsafe dynamic component loadings and malicious. By applying dynamic binary instrumentation to collect runtime information on component loading, and analyze the collected information to detect vulnerable component loadings can prevent unsafe dynamic components.
Keywords
data acquisition; invasive software; operating systems (computers); program diagnostics; software reusability; storage management; arbitrary file; automatic unsafe dynamic software component loading diagnosis; automatic unsafe dynamic software component loading prevention; code reusability; dynamic binary instrumentation; efficient memory usage; file system; malicious component; operating system; regular dynamic loading; remote exploitation; runtime information collection; system flexibility; system modularity; target component; Instruments; Linux; Loading; Message systems; Operating systems; Security; Dynamic analysis; Software analysis; Unsafe component loadings;
fLanguage
English
Publisher
ieee
Conference_Titel
Information & Communication Technologies (ICT), 2013 IEEE Conference on
Conference_Location
JeJu Island
Print_ISBN
978-1-4673-5759-3
Type
conf
DOI
10.1109/CICT.2013.6558192
Filename
6558192
Link To Document