Recent Developments in Low-Level Software Security

نویسندگان

  • Pieter Agten
  • Nick Nikiforakis
  • Raoul Strackx
  • Willem De Groef
  • Frank Piessens
چکیده

An important objective for low-level software security research is to develop techniques that make it harder to launch attacks that exploit implementation details of the system under attack. Baltopoulos and Gordon have summarized this as the principle of source-based reasoning for security: security properties of a software system should follow from review of the source code and its source-level semantics, and should not depend on details of the compiler or execution platform. Whether the principle holds – or to what degree – for a particular system depends on the attacker model. If an attacker can only provide input to the program under attack, then the principle holds for any safe programming language. However, for more powerful attackers that can load new native machine code into the system, the principle of source-based reasoning typically breaks down completely. In this paper we discuss state-of-the-art approaches for securing code written in C-like languages for both attacker models discussed above, and we highlight some very recent developments in low-level software security that hold the promise to restore source-based reasoning even against attackers that can provide arbitrary machine code to be run in the same process as the program under attack.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Comparative Study of Security Council's Dual Standards toward Recent Developments in Libya and Bahrain

With international peace and security covering a broader concept and restriction of governments' authority, issues such as human rights have become intertwined with international peace and security and are no longer an internal issue of governments. It is such that international society may react toward it and make some decisions. What seems important is how Security Council deals with such iss...

متن کامل

Recent Developments in Geopolitics of Energy and their Effects on the Political and Economic Future of the Middle East Countries

Energy has always been of particular importance to humanity. Oil and gas have been some of the energies that greatly influenced the national security of countries, which produce and consume energy. With the transformation of geostrategic discourse into geo-economic discourse in recent decades and the key role of economics in global relations, oil as the basis of modern industry has enjoyed a hi...

متن کامل

نسبت دگرگونی‌های منطقه‌ غرب آسیا با امنیت ملی جمهوری اسلامی ایران

Popular upheavals and regional developments in the Islamic world began in 2011, which began with the uprising of the Tunisian people, and then spread to other countries in the Arab world, including Egypt, Bahrain and Yemen. Major changes in the periphery of Iran were considered. Which affects the national security of the various countries of the region, including Iran. This paper, by descripti...

متن کامل

Browse searchable encryption schemes: Classification, methods and recent developments

With the advent of cloud computing, data owners tend to submit their data to cloud servers and allow users to access data when needed. However, outsourcing sensitive data will lead to privacy issues. Encrypting data before outsourcing solves privacy issues, but in this case, we will lose the ability to search the data. Searchable encryption (SE) schemes have been proposed to achieve this featur...

متن کامل

تاثیر شکنندگی دولت سوریه در تغییر تعاملات امنیتی خاورمیانه

The recent geopolitic developments of the Middle East under thetitle of Islamic awakening have intensified fragility of Syria and eventually turn it to a failed state. Syrian internal crisis has not only influenced on its national security but also affected entire Middle East security interactions. With regard to this, the main question of the research is: “What is the impact of fragile situati...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012