Memshepherd: comprehensive memory bug fault‐tolerance system. Issue 9 (6th November 2013)
- Record Type:
- Journal Article
- Title:
- Memshepherd: comprehensive memory bug fault‐tolerance system. Issue 9 (6th November 2013)
- Main Title:
- Memshepherd: comprehensive memory bug fault‐tolerance system
- Authors:
- Zou, Deqing
Zheng, Weide
Jiang, Wenbin
Jin, Hai
Chen, Gang - Abstract:
- <abstract abstract-type="main"> <title>Abstract</title> <p>Among all software vulnerabilities, memory bugs are most common and dangerous. Programs written in unsafe languages such as C and C++ are vulnerable to stack‐based buffer overflow, heap buffer overflow, dangling pointer, and double free. Although there are a number of proposed solutions to tolerate heap related bugs, most of the existing solutions terminates the vulnerable program after a stack‐based buffer overflow attempt. There is no comprehensive solution to actively tolerate all of the four kinds of bugs mentioned previously currently. This paper presents Memshepherd, a system that can probabilistically prevent software from both stack and heap memory bugs and guarantee soundness of the software execution. It dynamically reallocates stack‐based buffers in the heap space during software execution, thus transforms a stack memory problem into a heap memory problem. By adaptively sizing buffers to be <italic>M</italic> times of their defined size and randomly placing them, Memshepherd keeps the buffers far from each other. When a buffer is to be deallocated, Memshepherd checks invalid and double frees. A Linux prototype is implemented and tested against four kinds of memory bugs. The experiment results prove that Memshepherd is effective in eliminating crashes, erroneous execution, as well as security vulnerability. Copyright © 2013 John Wiley & Sons, Ltd.</p> </abstract>
- Is Part Of:
- Security and communication networks. Volume 7:Issue 9(2014:Sep.)
- Journal:
- Security and communication networks
- Issue:
- Volume 7:Issue 9(2014:Sep.)
- Issue Display:
- Volume 7, Issue 9 (2014)
- Year:
- 2014
- Volume:
- 7
- Issue:
- 9
- Issue Sort Value:
- 2014-0007-0009-0000
- Page Start:
- 1412
- Page End:
- 1419
- Publication Date:
- 2013-11-06
- Subjects:
- Computer networks -- Security measures -- Periodicals
Computer security -- Periodicals
Cryptography -- Periodicals
005.805 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1002/(ISSN)1939-0122 ↗
https://www.hindawi.com/journals/scn/ ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1002/sec.849 ↗
- Languages:
- English
- ISSNs:
- 1939-0114
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library HMNTS - ELD Digital store
- Ingest File:
- 3058.xml