Autodafé: an Act of Software Torture

نویسنده

  • Martin Vuagnoux
چکیده

Automated vulnerability searching tools have led to a dramatic increase of the rate at which such flaws are discovered. One particular searching technique is fault injection – i.e. insertion of random data into input files, buffers or protocol packets, combined with a systematic monitoring of memory violations. Even if these tools allow to uncover a lot of vulnerabilities, they are still very primitive; despite their poor efficiency, they are useful because of the very high density of such vulnerabilities in modern software. This paper presents an innovative buffer overflow uncovering technique, which uses a more thorough and reliable approach. This technique, called fuzzing by weighting attacks with markers, is a specialized kind of fault injection, which does not need source code or special compilation for the monitored program. As a proof of concept of the efficiency of this technique, a tool called Autodafé has been developed. It allows to detect automatically an impressive number of buffer overflow vulnerabilities. keywords: fuzzer, buffer overflow, weighting attacks with markers technique, fault injection, autodafe.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Contributory torture.

Sir, Contributory torture occurs when the behavior of the offender influences the behavior of the interrogator or, in a broader sense, anyone disciplining the offender. The word contributory is used because if the offender acts up, he/she is part of the reason for the type of punishment he/she receives. For example, if two people are arrested and one follows the directions of the officer and th...

متن کامل

Alteration in serum pituitary hormone levels in postmenopausal women with stroke.

Ticlopidine, Trials, and "Torture" To the Editor: The title of the editorial by van Gijn and Algra, "Ticlopidine, Trials, and Torture," may leave the impression that real torture is a phenomenon of the distant, cruel past, and that the word "torture" can now be used to describe any misconduct towards persons or, as in this case, scientific data. Torture, however, is a sad and unacceptable reali...

متن کامل

Sexual torture of men in Croatia and other conflict situations: an open secret.

Sexual torture constitutes any act of sexual violence which qualifies as torture. Public awareness of the widespread use of sexual torture as a weapon of war greatly increased after the war in the former Yugoslavia in the early 1990s. Sexual torture has serious mental, physical and sexual health consequences. Attention to date has focused more on the sexual torture of women than of men, partly ...

متن کامل

The psychosocial rehabilitation approach in treating torture survivors.

Organized torture practiced by oppressive regimes against political enemies constitutes a serious worldwide epidemic. According to Amnesty International, 150 out of 215 countries practiced human rights abuses in 2005. The United Nations defines torture as ‘‘any act by which severe pain or suffering, whether physical or mental, is intentionally inflicted on a person for such purpose as obtaining...

متن کامل

P165: A Pre-Review: The Psychodynamics of Torture under the Totalitarian Control

Torture is aimed to create a living dead. Pressing systematic control on individuals who are in opposition to the ruling authorities, persons’ sense of self would be damaged. Such an aversive situation is caused by intentional human action rather than natural causes. Torture occurs in more than 90 countries (Abu Ghraib prison is a prominent example) however, epidemiologic data are limited. The ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2006