29th Annual International Computer Software and Applications Conference (COMPSAC'05) Volume 1 SecureC: Control-Flow Protection Against General Buffer Overflow Attack Edinburgh, Scotland July 26-July 28 ISBN: 0-7695-2413-3
Increasing damage from computer virus or worms creating significant problems worldwide. These malicious programs take advantage of computer vulnerabilities to distort the control-flow of the target system. Among these vulnerabilities, buffer overflow is most frequently used as a means of intrusion. To protect against buffer overflow attacks, we have developed a source-to-source translator called SecureC. It incorporates two novel protection methods, "shadow stack" and "code pointer protection" that prevent control-flow transfer caused by buffer overflow attacks. Evaluation using 11 SPEC CPU2000 benchmark programs showed that SecureC prevents buffer overflow attacks with only 6.1% performance penalty.
Citation:
"SecureC: Control-Flow Protection Against General Buffer Overflow Attack," compsac, vol. 1, pp.149-155, 29th Annual International Computer Software and Applications Conference (COMPSAC'05) Volume 1, 2005 Usage of this product signifies your acceptance of the Terms of Use. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||