Monitoring Translation Lookahead Buffers to Detect Code Injection Attacks.

By identifying memory pages that external I/O operations have modified, a proposed scheme blocks malicious injected code activation, accurately distinguishing an attack from legitimate code injection with negligible performance impact and no changes to the user application.

Detalles Bibliográficos
Publicado en:Computer (00189162) Vol. 47; no. 7; pp. 66 - 73
Autores principales: Ahn, Youngjung, Lee, Yongsuk, Choi, Jin-Young, Lee, Gyungho, Ahn, Dongkyun
Formato: Artículo
Publicado: IEEE Jul2014
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=97237627&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 97237627
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00189162
        PUT
      jtl: Computer (00189162)
      issn: 00189162
      maglogo: N
    pubinfo:
      dt: Jul2014
      vid: 47
      iid: 7
      pid: 13605
      pub: IEEE
    artinfo:
      ui:
        97237627
        10.1109/MC.2013.228
      ppf: 66
      ppct: 7
      formats:
      tig:
        atl: Monitoring Translation Lookahead Buffers to Detect Code Injection Attacks.
      aug:
        au:
          Ahn, Youngjung
          Lee, Yongsuk
          Choi, Jin-Young
          Lee, Gyungho
          Ahn, Dongkyun
        affil:
          Korea University
          Intel
      su:
        Computer input-output equipment
        Malware
        Computer performance
        Computer systems
        Computer software research
      sug:
        subj:
          Computer input-output equipment
          Malware
          Computer performance
          Computer systems
          Computer software research
      keyword:
        Code injection
        data execution prevention
        Decision support systems
        hackers
        Handheld computers
        invasive software
        security
        TLB
      ab: By identifying memory pages that external I/O operations have modified, a proposed scheme blocks malicious injected code activation, accurately distinguishing an attack from legitimate code injection with negligible performance impact and no changes to the user application.
      pubtype: Academic Journal
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2014
    holdings:
      @attributes:
        islocal: N