[SW Security] CRCount: Pointer Invalidation with Reference Counting to Mitigate Use-after-free in Legacy C/C++, Network and Distributed System Security Symposium (NDSS), Feb. 2019

CRCount: Pointer Invalidation with Reference Counting to Mitigate Use-after-free in Legacy C/C++, Network and Distributed System Security Symposium (NDSS) 2019


Jangseop Shin, Donghyun Kwon, Jiwon Seo, Yeongpil Cho, Yunheung Paek


본 논문은 C/C++ 프로그램에 대한 공격으로 많이 사용되는 Use-after-free 취약점에 대한 방어 기법을 제안한다. 이를 위해 컴파일 단계에서 코드를 수정하여 Heap object에 대한 Reference Counting을 수행하여 이를 통해 Heap object의 해제를 dangling pointer가 없어질 때까지 지연시킨다. 또한 실험을 통해 이 approach의 효율성을 보여주었다.

0
0

International Papers

Mobile Cloud Computing An Effective Cloud Solution to Ensure the Integrity of Mobile Application via Execution Offloading, The 4th International Conference on Network, Communication and Computing (ICNCC), published in International Journal of Engineering and Technology (IJET), Feb 2017
Mobile Cloud Computing An Effective Cloud Solution to Ensure the Integrity of Mobile Application via Execution Offloading, International Journal of Engineering and Technology 9 (1), Feb 2017
Mobile Cloud Computing Optimization Techniques to Enable Execution Offloading for 3D Video Games, Multimedia Tools and Applications(MTAP), Jul 2016
Mobile Cloud Computing Energy-Reduction Offloading Technique for Streaming Media Servers, Mobile Information Systems, Mar 2016
Mobile Cloud Computing Energy Consumption Reduction Technique on Smart Devices for Communication-intensive Applications, Ubiquitous Information Techniques and Applications(CUTE), Dec 2015
Mobile Cloud Computing An Effective Cloud Solution to Ensure the Integrity of Mobile Application via Execution Offloading, International Conference on Network, Communication and Computing(ICNCC), Dec 2015
Mobile Cloud Computing Precise Execution Offloading for Applications with Dynamic Behavior in Mobile Cloud Computing, Pervasive and Mobile Computing, Apr 2015
Mobile Cloud Computing Reduction of Media Servers Overload with Energy-Saving Adaptive Streaming, Global IT Conference, Jan 2015
Mobile Cloud Computing Techniques to Minimize State Transfer Costs for Dynamic Execution Offloading in Mobile Cloud Computing, IEEE Transactions on Mobile Computing, Nov 2014
Mobile Cloud Computing CMcloud: Cloud Platform for Cost-Effective Offloading of Mobile Applications , 14th IEEE/ACM International Symposium on Cluster, Cloud and Grid Computing, May 2014 (Acceptance rate: 19%)
Mobile Cloud Computing Automatic Generation of Efficient Performance Predictors for Smartphone Applications, USENIX Annual Technical Conference(ATC), Jun 2013 (Acceptance rate: 14.16%) Best paper candidate
Mobile Cloud Computing Fast Dynamic Execution Offloading for Efficient Mobile Cloud Computing, IEEE International Conference on Pervasive Computing and Communication(PerCom), Mar 2013 (Acceptance rate: 11.2% = 19/170(full paper), 15.9% = 27/170(total))