A novel approach against the system buffer overflow
by Yi-Tung F. Chan, Galyna A. Akmayeva, Charles A. Shoniregun
International Journal of Internet Technology and Secured Transactions (IJITST), Vol. 2, No. 1/2, 2010

Abstract: The system buffer overflow (SBO) is a universal problem in information security. In the traditional defence mechanisms, the SBO prevents shell code execution and neglect unsuccessful attack that makes system procedures terminate abnormally. In this loophole, attackers can modify the data structure of the control programme procedure such as the return address or the function pointer and then the system programme procedure will be turned to the code-injection attacks (CIA) or the return-into-libc attacks. In this paper, we propose the memory protector (MP) which is a novel solution to prevent the SBO attack. The MP uses Linux operating system to implement the defence mechanism that will prevent the stack-based buffer overflow attack from the malicious CIA, defect and prevent the zero-day-attack, and keeping memory integrity. In this experiment, we choose Linux operating system (Linux 2.4.21) to implement the defence mechanism that will prevent the stack-based buffer overflow attack from the malicious CIA, defect and prevent the zero-day-attack, and keeping memory integrity.

Online publication date: Fri, 05-Feb-2010

The full text of this article is only available to individual subscribers or to users at subscribing institutions.

 
Existing subscribers:
Go to Inderscience Online Journals to access the Full Text of this article.

Pay per view:
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Internet Technology and Secured Transactions (IJITST):
Login with your Inderscience username and password:

    Username:        Password:         

Forgotten your password?


Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.

If you still need assistance, please email subs@inderscience.com