作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (17): 147-151. doi: 10.3969/j.issn.1000-3428.2010.17.050

• 安全技术 • 上一篇    下一篇

Windows下缓冲区溢出保护机制及绕过技术

马一楠1,张立和2   

  1. (1. 河南大学计算机与信息工程学院,开封 475004;2. 大连理工大学信息与通信工程学院,大连 116024)
  • 出版日期:2010-09-05 发布日期:2010-09-02
  • 作者简介:马一楠(1989-),女,本科生,主研方向:网络与信息安全;张立和,副教授、博士

Buffer Overflow Protection Mechanism and Bypass Technology Under Windows

MA Yi-nan1, ZHANG Li-he2   

  1. (1. School of Computer and Information Engineering, Henan University, Kaifeng 475004; 2. School of Information and Communication Engineering, Dalian University of Technology, Dalian 116024)
  • Online:2010-09-05 Published:2010-09-02

摘要: 综述当前Windows平台下主要的缓冲区溢出保护机制,该保护机制的绕过技术可以提高漏洞分析与利用的成功率及操作系统的安全性。介绍当前主要的缓冲区溢出保护机制的绕过技术的发展现状。针对堆栈溢出及数据执行保护(DEP)机制的突破技术,分别给出突破原理和方法。通过实验验证了DEP突破技术的有效性。

关键词: 缓冲区溢出, 栈溢出, 堆溢出, 数据执行保护, 绕过技术

Abstract: In this paper, the main buffer overflow protection mechanism is summarized under the current Windows platform, and the method and technologies about bypassing these protection mechanisms are studied, which can increase the success rate of vulnerabilities analysis and use, and guide to improve the security of the operating system. The paper describes the development of the current main technologies on bypassing the buffer overflow protection mechanisms. The principles and methods about bypassing stack overflow protection, heap overflow protection Data Execution Prevention(DEP) are all given. Effectiveness of the methods of bypassing DEP is verified through an experiment.

Key words: buffer overflow, stack overflow, heap overflow, Data Execution Prevention(DEP), bypass technology

中图分类号: