from    
to    
search  

 


International Workshop
Phase Change-Induced Liquid Droplet Actuations on Structured Surfaces –Appli...
物理系colloquium: 阿秒脉冲的产生、应用及发展展望
天文系 Colloquium: Astrochemistry: from the interstellar medium to thecradle ...
报告题目:
Analysis and Defense of Vulnerabilities in Binary Code
 报告人:
David Brumley
Assistant Professor at Carnegie Mellon University
报告时间:
2008-10-22 14:30
报告地点:
FIT-1-312
主办单位:
软件学院
  简介:

Title: Analysis and Defense of Vulnerabilities in Binary Code

 

Abstract:

New vulnerabilities are constantly discovered and exploited by attackers. A major focus of my research is developing techniques for protecting vulnerable applications when the program is only readily available as binary (i.e., executable) code.  Since most programs are available in binary form, and binary-only analysis does not require cooperation of the source code vendor, this line of research is likely to impact a wide audience.

 

In this talk, I show two new security applications of binary code analysis: automatic patch-based exploit generation, and automatic input filter generation. In this first part, I show how binary analysis can be used to automatically generate exploits based upon patches released from Windows Update.  An immediate consequence of this line of research is that many current vendor patching practices are insecure because they allow attackers to create new exploits before all vulnerable hosts can receive a patch. All is not lost, however. In the second part of this talk, I show how to defend against exploits by automatically generating input filters. Input filters remove exploits from the input stream, thus allowing the vulnerable application to continue to operate normally even under attack. The generated input filters are guaranteed to only filter out exploits, thus safe to automatically deploy.

 

Bio: David Brumley is an Assistant Professor at Carnegie Mellon University, and has appointments in the ECE and CS departments. He earned his Ph.D. in Computer Science from Carnegie Mellon University, a Masters in Computer Science from Stanford University, and a Bachelors in Mathematics from the University of Northern Colorado. His current work focuses on software security. His interests include all areas of security, as well as programming languages, compilers, formal methods, and systems.

 

 

今日相关信息
全球治理问题及其对美国外交政策的影响
明理论坛第33期:金融监管现代化——英美...
 
同类别相关信息
清华信息大讲堂:Green Multi-Homing ...
国家实验室青年创新基金学术沙龙-网络化...
【清华五道口金融家大讲堂】Finding O...
Attacks and Defenses for Website Fi...
清华RONGv2.0系列论坛之“社会关系网络...
学术活动