RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재후보

    버퍼 오버플로우 공격 방지를 위한 취약 함수 변환기 구현 = Implementation of a function translator converting vulnerable functions for preventing buffer overflow attacks

    한글로보기

    https://www.riss.kr/link?id=A104309448

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    C language is frequently used to develop application and system programs. However,programs using C language are vulnerable to buffer overflow attacks. To prevent buffer overflow, programmers have to check boundaries of buffer areas when they develop programs. But vulnerable programs frequently result from improper programming habits and mistakes of programmers. Existing researches for preventing buffer overflow attacks only inform programmers of warnings about vulnerabilities and not remove vulnerabilities in advance so that the programs still include vulnerabilities. In this paper,we propose a function translator which prevents creating programs including buffer overflow vulnerabilities. To prevent creating binary from source including vulnerabilities,the proposed translator searches vulnerable functions which cause buffer overflows, and converts them into secure functions. Accordingly, developing vulnerable programs by programmers which lack in knowledge on security can be prevented.
    번역하기

    C language is frequently used to develop application and system programs. However,programs using C language are vulnerable to buffer overflow attacks. To prevent buffer overflow, programmers have to check boundaries of buffer areas when they develop p...

    C language is frequently used to develop application and system programs. However,programs using C language are vulnerable to buffer overflow attacks. To prevent buffer overflow, programmers have to check boundaries of buffer areas when they develop programs. But vulnerable programs frequently result from improper programming habits and mistakes of programmers. Existing researches for preventing buffer overflow attacks only inform programmers of warnings about vulnerabilities and not remove vulnerabilities in advance so that the programs still include vulnerabilities. In this paper,we propose a function translator which prevents creating programs including buffer overflow vulnerabilities. To prevent creating binary from source including vulnerabilities,the proposed translator searches vulnerable functions which cause buffer overflows, and converts them into secure functions. Accordingly, developing vulnerable programs by programmers which lack in knowledge on security can be prevented.

    더보기

    참고문헌 (Reference)

    1 김익수, "관리자 인증 강화를 위한 추가적인 패스워드를 가지는 보안커널모듈 설계 및 구현" 한국정보처리학회 10 (10): 675-682, 2003

    2 "http://www.polyspace.com/"

    3 "http://www.coverity.com/"

    4 Kurt Wall, "The GCC Book" APress 2003

    5 E. Gaugh, "Testing C Programs for Buffer Overflow Vulnerabilities" 2003

    6 C. Cowan, "StackGuard:Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks" 1998

    7 R. Seacord, "Secure Coding in C and C++" Addison Wesley 2005

    8 J. Viega, "ITS4:A static vulnerability scanner for c and c++ code" 2000

    9 J. Pincus, "Beyond stack smashing: Recent advances in exploiting buffer overruns" 2 (2): 20-27, 2004

    10 Y. Xie, "ARCHER:Using Symbolic,Path-sensitive Analysis to Detect Memory Acess Errors" 2003

    1 김익수, "관리자 인증 강화를 위한 추가적인 패스워드를 가지는 보안커널모듈 설계 및 구현" 한국정보처리학회 10 (10): 675-682, 2003

    2 "http://www.polyspace.com/"

    3 "http://www.coverity.com/"

    4 Kurt Wall, "The GCC Book" APress 2003

    5 E. Gaugh, "Testing C Programs for Buffer Overflow Vulnerabilities" 2003

    6 C. Cowan, "StackGuard:Automatic Adaptive Detection and Prevention of Buffer-Overflow Attacks" 1998

    7 R. Seacord, "Secure Coding in C and C++" Addison Wesley 2005

    8 J. Viega, "ITS4:A static vulnerability scanner for c and c++ code" 2000

    9 J. Pincus, "Beyond stack smashing: Recent advances in exploiting buffer overruns" 2 (2): 20-27, 2004

    10 Y. Xie, "ARCHER:Using Symbolic,Path-sensitive Analysis to Detect Memory Acess Errors" 2003

    11 D. Wagner, "A First Step towards Automated Detection of Buffer Overrun Vulnerabilities" 2000

    더보기

    동일학술지(권/호) 다른 논문

    동일학술지 더보기

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    인용정보 인용지수 설명보기

    학술지 이력

    학술지 이력
    연월일 이력구분 이력상세 등재구분
    2027 평가 재인증평가 신청대상 (재인증)
    2021-01-01 등재 등재학술지 유지 (재인증) KCI등재
    2018-01-01 등재 등재학술지 선정 (계속평가) KCI등재
    2016-01-01 등재 등재후보학술지 선정 (신규평가) KCI등재후보
    2015-12-01 등재 등재후보 탈락 (기타)
    2014-01-01 등재 등재후보학술지 유지 (계속평가) KCI등재후보
    2013-01-01 등재 등재후보 1차 PASS (등재후보1차) KCI등재후보
    2012-01-01 등재 등재후보 1차 FAIL (기타) KCI등재후보
    2011-01-01 등재 등재후보학술지 유지 (등재후보2차) KCI등재후보
    2010-01-01 등재 등재후보 1차 PASS (등재후보1차) KCI등재후보
    2008-06-30 학회명변경 한글명 : 디지털산업정보학회 -> (사)디지털산업정보학회
    영문명 : 미등록 -> The Korea Society of Digital Industry and Information Management
    KCI등재후보
    2008-01-01 등재 등재후보학술지 선정 (신규평가) KCI등재후보
    더보기

    학술지 인용정보

    학술지 인용정보
    기준연도 WOS-KCI 통합IF(2년) KCIF(2년) KCIF(3년)
    2016 0.46 0.46 0.37
    KCIF(4년) KCIF(5년) 중심성지수(3년) 즉시성지수
    0.29 0.26 0.301 0.24
    더보기

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼