See this document in CiteSeerX!

Vulnerability-Specific Execution Filtering for Exploit Prevention on Commodity Software (2005)  (Make Corrections)  
James Newsome, David Brumley, Dawn Song



  Home/Search   Context   Related

 
View or download:
cmu.edu/anon/2005/CMUCS05169.pdf
Cached:  PS.gz  PS  PDF   Image  Update  Help

From:  cmu.edu/anon/2005/ (more)
(Enter author homepages)

Rate this article: (best)
  Comment on this article  
(Enter summary)

Abstract: Exploits for new vulnerabilities, especially when incorporated within a fast spreading worm, can compromise nearly all vulnerable hosts within a short amount of time. This problem demonstrates the need for fast defenses which can react to a new vulnerability quickly. In addition, a realistic defense system should (a) not require source code since in practice most vulnerable systems do not have source code access nor is there adequate time to involve the software vendor, (b) be accurate, i.e.,... (Update)

Similar documents based on text:
5.0:   Unknown -   (Correct)

BibTeX entry:   (Update)

@misc{ newsome-vulnerabilityspecific,
  author = "James Newsome and David Brumley and Dawn Song",
  title = "Vulnerability-Specific Execution Filtering for Exploit Prevention on Commodity
    Software",
  url = "citeseer.ist.psu.edu/newsome05vulnerabilityspecific.html" }
Citations (may not include all citations):
259   A survey of program slicing techniques - Tip - 1995
141   StackGuard: automatic adaptive detection and prevention of b.. - Cowan, Pu et al. - 1998
69   How to 0wn the Internet in your spare time - Staniford, Paxson et al. - 2002
54   Transparent run-time defense against stack smashing attacks - Baratloo, Singh et al. - 2000
32   Secure execution via program shepherding - Kiriansky, Bruening et al. - 2002
29   distributed worm signature detection (context) - Kim, Karp et al. - 2004
22   EXDAMS - extendable debugging and monitoring system (context) - Balzer - 1969
22   Inside the slammer worm (context) - Moore, Paxson et al. - 2003
15   Shield: Vulnerability-driven network filters for preventing .. - Wang, Guo et al. - 2004
13   The EarlyBird system for real-time detection of unknown worm.. (context) - Singh, Estan et al. - 2003
13   Dynamic taint analysis for automatic detection (context) - Newsome, Song - 2005
11   Valgrind: A program supervision framework (context) - Nethercote, Seward - 2003
11   CERTCC statistic (context) - CERT, http et al.
10   Secure program execution via dynamic information flow tracki.. (context) - Suh, Lee et al. - 2004
9   Hunting for metamorphic (context) - Szor - 2001

[Article contains additional citations not shown here]

Documents on the same site (http://reports-archive.adm.cs.cmu.edu/anon/2005/):   More
Taxonomy and Effectiveness of Worm Defense Strategies - Brumley, Liu, Poosankam, Song (2005)   (Correct)
Learning To Prevent Failure State for a Dynamically.. - Searock, Browning, Veloso (2005)   (Correct)
Device-Enabled Authorization in the Grey System - Bauer, Garriss, McCune.. (2005)   (Correct)

Online articles have much greater impact   More about CiteSeer.IST   Add search form to your site   Submit documents   Feedback  

CiteSeer.IST - Copyright Penn State and NEC