检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:王俊卿 邬江 黄永洪 祝林 Wang Junqing;Wu Jiang;Huang Yonghong;Zhu Lin(China Electronics Technology Group Great Wall Internet Security Technology Research Institute(Beijing)Co.,Ltd.,Beijing 100097,China;School of Cyberspace Security and Information Law,Chongqing University of Posts and Telecommunications,Chongqing 400065,China)
机构地区:[1]中电长城网际安全技术研究院(北京)有限公司,北京100097 [2]重庆邮电大学网络空间安全与信息法学院,重庆400065
出 处:《网络安全与数据治理》2025年第3期1-7,共7页CYBER SECURITY AND DATA GOVERNANCE
摘 要:分析栈溢出原因和现有检测技术,提出一种基于操作系统行为测量的栈溢出检测方法。以操作系统行为测量为理论基础,对操作系统行为进行形式化定义。利用虚拟机自省技术实时监控程序运行时的内存访问,实现透明带外检测栈缓冲区溢出行为。实验结果表明,该方法能有效识别栈缓冲区溢出,且具有较低的误报率。这一研究成果为提高系统安全性提供了新的视角和解决方案。This paper analyzes the causes of stack overflow and existing detection technologies,and proposes a stack overflow detection method based on operating system behavior measurement.Based on the theoretical foundation of operating system behavior measurement,the formal definition of operating system behavior is presented.Utilize virtual machine introspection technology to monitor memory access in real-time during program execution,enabling transparent out-of-band detection of stack buffer overflow behavior.Experimental results show that this method can effectively identify buffer overflows and has a low false positive rate.This research outcome provides a new perspective and solution for improving system security.
分 类 号:TP391[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.147