[1]施祖清 张涛 王金双 姚金魁 袁志坚.基于ARM架构的信息流追踪系统的设计与实现[J].计算机技术与发展,2012,(06):147-150.
SHI Zu-qing,ZHANG Tao,WANG Jin-shuang,et al.Design and Implementation of an.Information Flow Tracking System Based on ARM Architecture[J].,2012,(06):147-150.
点击复制
基于ARM架构的信息流追踪系统的设计与实现(
)
《计算机技术与发展》[ISSN:1006-6977/CN:61-1281/TN]
- 卷:
-
- 期数:
-
2012年06期
- 页码:
-
147-150
- 栏目:
-
安全与防范
- 出版日期:
-
1900-01-01
文章信息/Info
- Title:
-
Design and Implementation of an.Information Flow Tracking System Based on ARM Architecture
- 文章编号:
-
1673-629X(2012)06-0147-04
- 作者:
-
施祖清 张涛 王金双 姚金魁 袁志坚
-
解放军理工大学指挥自动化学院
- Author(s):
-
SHI Zu-qing; ZHANG Tao; WANG Jin-shuang; YAO Jin-kui; YUAN Zhi-jian
-
Institute of Command Automation, PLA University of Science and Technology
-
- 关键词:
-
信息流追踪; ARM架构; 页表项; 指令层; 污点
- Keywords:
-
information flow tracking; ARM architecture; page table entry ; instruction layer; taint
- 分类号:
-
TP309
- 文献标志码:
-
A
- 摘要:
-
当前,智能手机平台面临着众多的安全威胁。动态信息流追踪是一种能够检测缓冲区溢出等安全威胁的有效技术。文中分析了动态信息流追踪技术的基本原理,设计并实现了基于ARM架构的信息流追踪系统。该系统通过在页表项上扩展添加污点标记位来标识来自不可信数据源的数据,扩充ARM架构指令集,在指令层追踪数据的传播过程并相应地完成污点传播。当系统跳转到来自不可信数据源的内存段执行时,CPU将产生异常通知用户,根据系统安全策略决定是否允许该操作继续执行。研究表明该系统能够有效实现ARM架构智能平台的安全防护
- Abstract:
-
At present,smartphone platform is facing numerous security threats. Dynamic information flow tracking (DIFT) is an effective technique for detecting buffer overflow. It analyzed the basic principle of DIFT, designed and implemented an information tracking system for the ARM architecture. A taint marking bit was added to the page table entry, which was used to indicate data coming from untrusted source. The ARM instruction set was expanded to track the taint propagation accompanied with the propagation of the data. CPU will throw exceptions when the system jumps to memory segments containing data from untrusted source,and enforce the access decision according to system security policy. Thus the system can be protected from attacks originated from buffer overflows etc
备注/Memo
- 备注/Memo:
-
国家高技术研究发展计划“863”项目(2009AA01Z40)施祖清(1986-),男,硕士研究生,CCF会员,研究方向为嵌入式系统应用技术张涛,教授,硕士研究生导师,研究方向为信息安全、计算机系统结构
更新日期/Last Update:
1900-01-01