Heap overflow attack is one of the major memory corruption attacks that have become prevalent for decades. To defeat this attack,many protection methods are proposed in recent years. However,most of these existing met...Heap overflow attack is one of the major memory corruption attacks that have become prevalent for decades. To defeat this attack,many protection methods are proposed in recent years. However,most of these existing methods focus on user-level heap overflow detection. Only a few methods are proposed for kernel heap protection. Moreover,all these kernel protection methods need modifying the existing OS kernel so that they may not be adopted in practice. To address this problem,we propose a lightweight virtualization-based solution that can protect the kernel heap buffers allocated for the target kernel modules. The key idea of our approach is to combine the static binary analysis and virtualization technology to trap a memory allocation operation of the target kernel module,and then add one secure canary word to the end of the allocated buffer. After that,a monitor process is launched to check the integrity of the canaries. The evaluations show that our system can detect kernel heap overflow attacks effectively with minimal performance cost.展开更多
Let R be a ring with an identity and C(R) be the category of right R-modules. In this paper we introduce the notion of semi-McCoy module. With this notion we show that McCoy modules of C(R) are closed under kernel...Let R be a ring with an identity and C(R) be the category of right R-modules. In this paper we introduce the notion of semi-McCoy module. With this notion we show that McCoy modules of C(R) are closed under kernels of epimorphisms, and they are also closed under extensions and direct sums with certain conditions. We also get some results on the subcategories of McCoy modules of C(R[x]) and C(R[x; x(-1)]).展开更多
Aiming at acquiring and processing requirements of temperature sensor signal on the industrial control spot, it designs a RTD module based on ADuCM361 microprocessor. It integrates two types of processors including A ...Aiming at acquiring and processing requirements of temperature sensor signal on the industrial control spot, it designs a RTD module based on ADuCM361 microprocessor. It integrates two types of processors including A -Y ADC with 24 bites high precision and ARM Cortex -M3 kernel with 32bites. Besides, it designs the hardware circuit and software flowchart of RTD temperature acquisition module. Programming practice proves that the model has many advantages concluding simple construction, strong practicability, low cost, wide measuring range, high precision, high reliability and so on.展开更多
A security kernel architeclrne built on trusted computing platform in thelight of thinking about trusted computing is presented According to this architecture,a newsecurity module TCB(Trusted Computing Base)is added t...A security kernel architeclrne built on trusted computing platform in thelight of thinking about trusted computing is presented According to this architecture,a newsecurity module TCB(Trusted Computing Base)is added to the operation system kerneland twooperation interface modes are provided for the sake of self-protection.The security kernel isdivided into two parts and trusted mechanism Is separated from security functionality.Ihe TCBmodule implements the trusted mechanism such as measurement and attestation,while the othercomponents of security kernel provide security functionality based on these mechanisms.Thisarchitecture takes full advantage of functions provided by trusted platform and clearly defines thesecurity perimeter of TCB so as to assure stlf-securily from architcetmal vision.We also presentfunction description of TCB and discuss the strengths and limitations comparing with other relatedresearches.展开更多
基金supported in part by National Natural Science Foundation of China (NSFC) under Grant No.61602035the National Key Research and Development Program of China under Grant No.2016YFB0800700+1 种基金the Opening Project of Shanghai Key Laboratory of Integrated Administration Technologies for Information SecurityOpen Found of Key Laboratory of IOT Application Technology of Universities in Yunnan Province under Grant No.2015IOT03
摘要Heap overflow attack is one of the major memory corruption attacks that have become prevalent for decades. To defeat this attack,many protection methods are proposed in recent years. However,most of these existing methods focus on user-level heap overflow detection. Only a few methods are proposed for kernel heap protection. Moreover,all these kernel protection methods need modifying the existing OS kernel so that they may not be adopted in practice. To address this problem,we propose a lightweight virtualization-based solution that can protect the kernel heap buffers allocated for the target kernel modules. The key idea of our approach is to combine the static binary analysis and virtualization technology to trap a memory allocation operation of the target kernel module,and then add one secure canary word to the end of the allocated buffer. After that,a monitor process is launched to check the integrity of the canaries. The evaluations show that our system can detect kernel heap overflow attacks effectively with minimal performance cost.
基金Supported by the National Natural Science Foundation of China(Grant No.11471017)the Natural Science Foundation of Anhui Higher Education Institutions of China(Grant No.KJ2018A0304)the Doctoral Research Foundation and the Research Culture Foundation of Anhui Normal University(Grant No.2014xmpy11)
摘要Let R be a ring with an identity and C(R) be the category of right R-modules. In this paper we introduce the notion of semi-McCoy module. With this notion we show that McCoy modules of C(R) are closed under kernels of epimorphisms, and they are also closed under extensions and direct sums with certain conditions. We also get some results on the subcategories of McCoy modules of C(R[x]) and C(R[x; x(-1)]).
基金The project has been supported by Chinese National Natural Science Foundation(No.5 l177099)Shahghai City Committee of science and technology project(No.10160501700).
摘要Aiming at acquiring and processing requirements of temperature sensor signal on the industrial control spot, it designs a RTD module based on ADuCM361 microprocessor. It integrates two types of processors including A -Y ADC with 24 bites high precision and ARM Cortex -M3 kernel with 32bites. Besides, it designs the hardware circuit and software flowchart of RTD temperature acquisition module. Programming practice proves that the model has many advantages concluding simple construction, strong practicability, low cost, wide measuring range, high precision, high reliability and so on.
基金Supported by the National Basic Research Programof China(G1999035801)
摘要A security kernel architeclrne built on trusted computing platform in thelight of thinking about trusted computing is presented According to this architecture,a newsecurity module TCB(Trusted Computing Base)is added to the operation system kerneland twooperation interface modes are provided for the sake of self-protection.The security kernel isdivided into two parts and trusted mechanism Is separated from security functionality.Ihe TCBmodule implements the trusted mechanism such as measurement and attestation,while the othercomponents of security kernel provide security functionality based on these mechanisms.Thisarchitecture takes full advantage of functions provided by trusted platform and clearly defines thesecurity perimeter of TCB so as to assure stlf-securily from architcetmal vision.We also presentfunction description of TCB and discuss the strengths and limitations comparing with other relatedresearches.