A Taxonomy of Buffer Overflow Preconditions

Free registration required

Executive Summary

Recent work on vulnerabilities has focused on buffer overflows, in which data exceeding the bounds of an array is loaded into the array. The loading continues past the end of the array, causing variables and state information to change. As the process is not programmed to check for these additional changes, the process acts incorrectly. The incorrect action often places the system in a non-secure state. This work develops a taxonomy of buffer overflow vulnerabilities based upon preconditions, or conditions that must hold for an exploitable buffer overflow to exist. The authors analyze several software and hardware countermeasures to validate the approach. They then discuss alternate approaches to ameliorating this vulnerability.

  • Format: PDF
  • Size: 173.7 KB