Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Enhancements to the Linux Kernel for Blocking Buffer Overflow Based Attacks

We present the design and implementation of a cost-effective mechanism which controls the invocation of critical, from the security viewpoint, system calls.

The integration into existing UNIX operating systems is carried out by instrumenting the code of the system calls so that the system call itself once invoked checks to see whether the invoking process and the argument values passed comply with the rules held in an access control database.

A working prototype able to detect and block buffer overflow attacks is available as a small set of ``patches'' to the Linux operating system kernel source.

Massimo Bernaschi, Italian National Research Council

Emanuele Gabrielli, Università di Roma "La Sapienza", Italy

Luigi V. Mancini, Università di Roma "La Sapienza", Italy

BibTeX
@inproceedings {271198,
author = {Massimo Bernaschi and Emanuele Gabrielli and Luigi V. Mancini},
title = {Enhancements to the Linux Kernel for Blocking Buffer Overflow Based Attacks},
booktitle = {4th Annual Linux Showcase \& Conference (ALS 2000)},
year = {2000},
address = {Atlanta, GA },
url = {https://www.usenix.org/conference/als-2000/enhancements-linux-kernel-blocking-buffer-overflow-based-attacks},
publisher = {USENIX Association},
month = oct
}
Download

Links

Paper: 
http://www.usenix.org/publications/library/proceedings/als00/2000papers/papers/full_papers/bernaschi/bernaschi.pdf
Paper (HTML): 
http://www.usenix.org/publications/library/proceedings/als00/2000papers/papers/full_papers/bernaschi/bernaschi_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us