@inproceedings{fb55b009a1994c528f73df16051f3b0f,
title = "Integrating offline analysis and online protection to defeat buffer overflow attacks",
abstract = "Nowadays Buffer overflow attacks are still recognized as one of the most severe threats in software security. Previous solutions suffer from limitations in that: 1) Some methods based on compiler extensions have limited practicality because they need to access source code; 2) Other methods that need to modify some aspects of the operating system or hardware require much deployment effort; 3) Almost all methods are unable to deploy a runtime protection for programs that cannot afford to restart. In this paper, we propose PHUKO, an on-the-fly buffer overflow prevention system which leverages virtualization technology. PHUKO offers the protected program a fully transparent environment and an easy deployment without the need to restart the program. The experiments show that our system can defend against realistic buffer overflow attacks effectively with moderate performance overhead.",
author = "Donghai Tian and Xi Xiong and Changzhen Hu and Peng Liu",
note = "Publisher Copyright: {\textcopyright} 2011, Springer-Verlag Berlin Heidelberg.; 13th International Conference on Information Security, ISC 2010 ; Conference date: 25-10-2010 Through 28-10-2010",
year = "2011",
doi = "10.1007/978-3-642-18178-8\_34",
language = "English (US)",
isbn = "9783642181771",
series = "Lecture Notes in Computer Science",
publisher = "Springer Verlag",
pages = "409--415",
editor = "Mike Burmester and Gene Tsudik and Spyros Magliveras and Ivana Ilic",
booktitle = "Information Security - 13th International Conference, ISC 2010, Revised Selected Papers",
address = "Germany",
}