作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (18): 163-165. doi: 10.3969/j.issn.1000-3428.2010.18.056

• 安全技术 • 上一篇    下一篇

shellcode攻击与防范技术

王 颖1,2,李祥和2,关 龙3,崔宝江1   

  1. (1. 北京邮电大学计算机学院,北京 100876;2. 解放军信息工程大学信息工程学院,郑州 450002;3. 大连理工大学电子与信息工程学院,辽宁 大连 116024)
  • 出版日期:2010-09-20 发布日期:2010-09-30
  • 作者简介:王 颖(1978-),女,博士研究生,主研方向:计算机网络安全;李祥和,教授;关 龙,硕士研究生;崔宝江,副教授、博士
  • 基金资助:

    国家“863”计划基金资助项目(2007AA01Z466);国家部委预研基金资助项目

Attack and Defending Technology of shellcode

WANG Ying1,2, LI Xiang-he2, GUAN Long3, CUI Bao-jiang1   

  1. (1. School of Computer, Beijing University of Posts and Telecommunications, Beijing 100876, China; 2. Institute of Information Engineering, PLA Information Engineering University, Zhengzhou 450002, China;3. School of Electronic and Information Engineering, Dalian University of Technology, Dalian 116024, China)
  • Online:2010-09-20 Published:2010-09-30

摘要:

针对Windows系统环境下,攻击者通过shellcode代码威胁系统安全的问题,研究shellcode攻击与防范方法。分析shellcode代码的工作原理、攻击过程及多种变化,介绍新型Windows系统采用的GS和ASLR保护对shellcode攻击的防范机制,并通过实验验证其防范效果。结果证明,实施shellcode攻击需要一定的条件,而GS和ALSR可破坏这些攻击条件的形成,有效阻止攻击。

关键词: shellcode代码, 编码, 定位

Abstract:

Aiming at the problem that shellcode threats the security of the operating system, this paper researches on the shellcode attack and the method against the attack. Principle, consisting and process of the shellcode attack are analysed. The GS and ALSR work against the shellcode attack, and the effect of the GS and ALSR protection mechanism is tested. Experimental results show that it needs some conditions when the attacker carries out the shellcode attack, and the new protection mechanism can limit this condition against the attack.

Key words: shellcode, coding, location

中图分类号: