Recent Developments in Low-Level Software Security
نویسندگان
چکیده
An important objective for low-level software security research is to develop techniques that make it harder to launch attacks that exploit implementation details of the system under attack. Baltopoulos and Gordon have summarized this as the principle of source-based reasoning for security: security properties of a software system should follow from review of the source code and its source-level semantics, and should not depend on details of the compiler or execution platform. Whether the principle holds – or to what degree – for a particular system depends on the attacker model. If an attacker can only provide input to the program under attack, then the principle holds for any safe programming language. However, for more powerful attackers that can load new native machine code into the system, the principle of source-based reasoning typically breaks down completely. In this paper we discuss state-of-the-art approaches for securing code written in C-like languages for both attacker models discussed above, and we highlight some very recent developments in low-level software security that hold the promise to restore source-based reasoning even against attackers that can provide arbitrary machine code to be run in the same process as the program under attack.
منابع مشابه
A Comparative Study of Security Council's Dual Standards toward Recent Developments in Libya and Bahrain
With international peace and security covering a broader concept and restriction of governments' authority, issues such as human rights have become intertwined with international peace and security and are no longer an internal issue of governments. It is such that international society may react toward it and make some decisions. What seems important is how Security Council deals with such iss...
متن کاملRecent Developments in Geopolitics of Energy and their Effects on the Political and Economic Future of the Middle East Countries
Energy has always been of particular importance to humanity. Oil and gas have been some of the energies that greatly influenced the national security of countries, which produce and consume energy. With the transformation of geostrategic discourse into geo-economic discourse in recent decades and the key role of economics in global relations, oil as the basis of modern industry has enjoyed a hi...
متن کاملنسبت دگرگونیهای منطقه غرب آسیا با امنیت ملی جمهوری اسلامی ایران
Popular upheavals and regional developments in the Islamic world began in 2011, which began with the uprising of the Tunisian people, and then spread to other countries in the Arab world, including Egypt, Bahrain and Yemen. Major changes in the periphery of Iran were considered. Which affects the national security of the various countries of the region, including Iran. This paper, by descripti...
متن کاملBrowse searchable encryption schemes: Classification, methods and recent developments
With the advent of cloud computing, data owners tend to submit their data to cloud servers and allow users to access data when needed. However, outsourcing sensitive data will lead to privacy issues. Encrypting data before outsourcing solves privacy issues, but in this case, we will lose the ability to search the data. Searchable encryption (SE) schemes have been proposed to achieve this featur...
متن کاملتاثیر شکنندگی دولت سوریه در تغییر تعاملات امنیتی خاورمیانه
The recent geopolitic developments of the Middle East under thetitle of Islamic awakening have intensified fragility of Syria and eventually turn it to a failed state. Syrian internal crisis has not only influenced on its national security but also affected entire Middle East security interactions. With regard to this, the main question of the research is: “What is the impact of fragile situati...
متن کامل