Where's the FEEB? The Effectiveness of Instruction Set Randomization

نویسندگان

  • Ana Nora Sovarel
  • David Evans
  • Nathanael Paul
چکیده

Instruction Set Randomization (ISR) has been proposed as a promising defense against code injection attacks. It defuses all standard code injection attacks since the attacker does not know the instruction set of the target machine. A motivated attacker, however, may be able to circumvent ISR by determining the randomization key. In this paper, we investigate the possibility of a remote attacker successfully ascertaining an ISR key using an incremental attack. We introduce a strategy for attacking ISR-protected servers, develop and analyze two attack variations, and present a technique for packaging a worm with a miniature virtual machine that reduces the number of key bytes an attacker must acquire to 100. Our attacks can break enough key bytes to infect an ISR-protected server in about six minutes. Our results provide insights into properties necessary for ISR implementations to be secure.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Student Ratings of Instruction: True or False

Introduction. Students' evaluation of teaching is a major concern in higher education. In this regard, during the past 30 years hundreds of papers have been published which because of various grounds from valid, reliable to useless, such papers cannot be easily summarized. The present study investigated for two purposes, first was to out line opinions of two groups of advocates and opposites a...

متن کامل

Measuring the Effectiveness of Explicit and Implicit Instruction through Explicit and Implicit Measures

Many studies have examined the effect of different approaches to teaching grammar including explicit and implicit instruction. However, research in this area is limited in a number of respects. One such limitation pertains to the issue of construct validity of the measures, i.e. the knowledge developed through implicit instruction has been measured through instruments which favor th...

متن کامل

Explicit vs. Contrastive-based Instruction of Formulaic Expressions in Developing EFL Learners’ Reading Ability

 As an integrative component of textual structure, formulaic expressions (FEs) play a key role in communicating the message and comprehending the text. Furthermore, interlingually contrastive features of FEs add to their both significance and complexity of their instruction. Given these facts, this study was an attempt to explore a sound mechanism on how to teach FEs; whether an explicit or CA-...

متن کامل

On Teaching to Diversity: Investigating the Effectiveness of MI-Inspired Instruction in an EFL Context

This study reports an experiment conducted to investigate the effectiveness of implementing MI-inspired instruction in an EFL context. To this end, a group of ten intermediate female students took part in a quasi-experimental study. At the beginning of the experiment, Multiple Intelligences Survey (Armstrong, 1993) was administered to determine the participants’ MI profiles. The participants we...

متن کامل

The Effectiveness of Emotion Regulation Instruction on Increasing of Marital Adjustment in Couples with Marital Conflict

Introduction: Marital maladjustment is one of the serious problem that serve as the cause of divorce and domestic violence in many families. The aim of this research was to study the effectiveness of emotion regulation instruction on marital adjustment of couple with marital conflicts. Methods: The design of this research was experimental with pre-post tests and randomly assignment of subje...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005