Home

Concurrency Attacks

Junfeng Yang; Ang Cui; John Martin Gallagher; Salvatore Stolfo; Lakshminarasimhan Sethumadhavan

Title:
Concurrency Attacks
Author(s):
Yang, Junfeng
Cui, Ang
Gallagher, John Martin
Stolfo, Salvatore
Sethumadhavan, Lakshminarasimhan
Date:
Type:
Technical reports
Department:
Computer Science
Permanent URL:
Series:
Columbia University Computer Science Technical Reports
Part Number:
CUCS-028-11
Publisher:
Department of Computer Science, Columbia University
Publisher Location:
New York
Abstract:
Just as errors in sequential programs can lead to security exploits, errors in concurrent programs can lead to concurrency attacks. In this paper, we present an in-depth study of concurrency attacks and how they may affect existing defenses. Our study yields several interesting findings. For instance, we find that concurrency attacks can corrupt non-pointer data, such as user identifiers, which existing memory-safety defenses cannot handle. Inspired by our findings, we propose new defense directions and fixes to existing defenses.
Subject(s):
Computer science
Item views:
234
Metadata:
text | xml

In Partnership with the Center for Digital Research and Scholarship at Columbia University Libraries/Information Services | Terms of Use