• DocumentCode
    618381
  • Title

    Automated diagnosis and prevention of unsafe dynamic software component loadings

  • Author

    Balakrishnan, Ranjith ; Anbarasu, J.

  • Author_Institution
    Dept. of Tifac-Core in Pervasive Comput. Technol., Velammal Eng. Coll., Chennai, India
  • fYear
    2013
  • fDate
    11-12 April 2013
  • Firstpage
    739
  • Lastpage
    743
  • Abstract
    For an improved system modularity and flexibility through code reuse, efficient memory usage, and reduced disk space dynamic loading of software components is widely used mechanism in operating system. However, Programming mistakes may create malicious components being loaded with regular dynamic loadings. In particular, dynamic loadings can be made as malicious components by placing an arbitrary file with the same or specified name in target components. Although this issue has not been considered serious because such vulnerabilities are dangerous than virus and exploiting it requires access to local file system. This kind of malicious will act as original dynamic loadings with the same name and makes remote exploitation realistic. To avoid remote attacks and intruders, in this paper we present the automated technique to detect unsafe dynamic component loadings and malicious. By applying dynamic binary instrumentation to collect runtime information on component loading, and analyze the collected information to detect vulnerable component loadings can prevent unsafe dynamic components.
  • Keywords
    data acquisition; invasive software; operating systems (computers); program diagnostics; software reusability; storage management; arbitrary file; automatic unsafe dynamic software component loading diagnosis; automatic unsafe dynamic software component loading prevention; code reusability; dynamic binary instrumentation; efficient memory usage; file system; malicious component; operating system; regular dynamic loading; remote exploitation; runtime information collection; system flexibility; system modularity; target component; Instruments; Linux; Loading; Message systems; Operating systems; Security; Dynamic analysis; Software analysis; Unsafe component loadings;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information & Communication Technologies (ICT), 2013 IEEE Conference on
  • Conference_Location
    JeJu Island
  • Print_ISBN
    978-1-4673-5759-3
  • Type

    conf

  • DOI
    10.1109/CICT.2013.6558192
  • Filename
    6558192