基于操作系统行为测量的栈溢出检测方法  

Stack overflow detection method based on operating system behavior measurement

在线阅读下载全文

作  者:王俊卿 邬江 黄永洪 祝林 Wang Junqing;Wu Jiang;Huang Yonghong;Zhu Lin(China Electronics Technology Group Great Wall Internet Security Technology Research Institute(Beijing)Co.,Ltd.,Beijing 100097,China;School of Cyberspace Security and Information Law,Chongqing University of Posts and Telecommunications,Chongqing 400065,China)

机构地区:[1]中电长城网际安全技术研究院(北京)有限公司,北京100097 [2]重庆邮电大学网络空间安全与信息法学院,重庆400065

出  处:《网络安全与数据治理》2025年第3期1-7,共7页CYBER SECURITY AND DATA GOVERNANCE

摘  要:分析栈溢出原因和现有检测技术,提出一种基于操作系统行为测量的栈溢出检测方法。以操作系统行为测量为理论基础,对操作系统行为进行形式化定义。利用虚拟机自省技术实时监控程序运行时的内存访问,实现透明带外检测栈缓冲区溢出行为。实验结果表明,该方法能有效识别栈缓冲区溢出,且具有较低的误报率。这一研究成果为提高系统安全性提供了新的视角和解决方案。This paper analyzes the causes of stack overflow and existing detection technologies,and proposes a stack overflow detection method based on operating system behavior measurement.Based on the theoretical foundation of operating system behavior measurement,the formal definition of operating system behavior is presented.Utilize virtual machine introspection technology to monitor memory access in real-time during program execution,enabling transparent out-of-band detection of stack buffer overflow behavior.Experimental results show that this method can effectively identify buffer overflows and has a low false positive rate.This research outcome provides a new perspective and solution for improving system security.

关 键 词:栈溢出 虚拟机自省 检测方法 

分 类 号:TP391[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象